Drupal Search API Autocomplete 中存在“网页生成期间输入中性化处理不当”(跨站脚本攻击,Cross-site Scripting,XSS)漏洞,可导致反射型 XSS 漏洞。该问题影响 Search API Autocomplete 以下版本:从 0.0.0 至 1.12.0。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Drupal | Search API Autocomplete | 0.0.0< 1.12.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Search API Autocomplete | 0.0.0 ~ 1.12.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15088 | Development Environment - Critical - Unsupported - SA-CONTRIB-2026-089 | |
| CVE-2026-15917 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011 | |
| CVE-2026-15916 | Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010 | |
| CVE-2026-16641 | Commerce Elavon - Critical - Unsupported - SA-CONTRIB-2026-084 | |
| CVE-2026-16643 | Lunr exposed filters - Critical - Unsupported - SA-CONTRIB-2026-086 | |
| CVE-2026-16646 | PanKM - Critical - Unsupported - SA-CONTRIB-2026-083 | |
| CVE-2026-16645 | PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Access bypa | |
| CVE-2026-16644 | Webform REST - Moderately critical - Access bypass - SA-CONTRIB-2026-087 | |
| CVE-2026-16638 | Media Folders - Moderately critical - Cross site scripting - SA-CONTRIB-2026-080 | |
| CVE-2026-16639 | Internationalization Single Sign-On - Critical - Access bypass - SA-CONTRIB-2026-081 | |
| CVE-2026-16642 | Email Login OTP - Critical - Unsupported - SA-CONTRIB-2026-085 | |
| CVE-2026-18261 | Powerful Surveys - Critical - Unsupported - SA-CONTRIB-2026-092 | |
| CVE-2026-18985 | Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 | |
| CVE-2026-18260 | Disable Login Page - Critical - Unsupported - SA-CONTRIB-2026-091 | |
| CVE-2026-18259 | Token Content Access - Moderately critical - Access bypass - SA-CONTRIB-2026-090 | |
| CVE-2026-55805 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012 |
No comments yet