Drupal Colorbox Inline是Drupal公司的一个Drupal弹窗展示模块。 Drupal Colorbox Inline 2.1.1之前版本存在跨站脚本漏洞,该漏洞源于网页生成过程中输入中和不当,可能导致跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Drupal | Colorbox Inline | 0.0.0< 2.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | Colorbox Inline | 0.0.0 ~ 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6095 | Orejime - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-032 | |
| CVE-2026-6365 | Drupal core - Critical - Cross-site scripting - SA-CORE-2026-001 | |
| CVE-2026-6366 | Drupal core - Moderately critical - Gadget Chain - SA-CORE-2026-002 | |
| CVE-2026-6367 | Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-003 | |
| CVE-2026-6871 | Obfuscate - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-033 | |
| CVE-2026-8491 | Node View Permissions - Moderately critical - Access bypass - SA-CONTRIB-2026-034 | |
| CVE-2026-8492 | Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA | |
| CVE-2026-8495 | Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037 |
No comments yet