VYPR
Medium severity6.1NVD Advisory· Published May 19, 2026· Updated May 20, 2026

CVE-2026-6367

CVE-2026-6367

Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).

This issue affects Drupal core: from 11.3.0 before 11.3.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
drupal/corePackagist
>= 11.3.0, < 11.3.711.3.7

Affected products

4
  • Drupal/Drupalinferred2 versions
    >=11.3.0,<11.3.7+ 1 more
    • (no CPE)range: >=11.3.0,<11.3.7
    • cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*range: >=11.3.0,<11.3.7
  • Range: >=11.3.0, <11.3.7
  • osv-coords
    Range: >= 11.3.0, < 11.3.7

Patches

Vulnerability mechanics

References

3

News mentions

1