Medium severity6.1NVD Advisory· Published Sep 2, 2026· Updated Oct 1, 2026
CVE-2026-81160
CVE-2026-81160
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 0.0.0 - 2.1.0
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-117nvdVendor Advisory
News mentions
2- Drupal: 25 Vulnerabilities Disclosed Together on September 2, 2026Vypr Intelligence · Sep 2, 2026
- Drupal: Eight Security Vulnerabilities Disclosed in Single AdvisoryVypr Intelligence · Aug 27, 2026