CVE-2026-0749

All FrameworksDrupalCWE-79CVE-2026-0749

CVE-2026-0749

State: PUBLISHED · Published: 2026-01-28 · Updated: 2026-01-28 · Assigner: drupal
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2026/0xxx/CVE-2026-0749.json