CERT-Bund: XSS in Drupal extensions among 35 flaws in WID-SEC-2026-3554
CERT-Bund published advisory WID-SEC-2026-3554 on 23 September 2026 covering 35 CVEs in Drupal extensions, including cross-site scripting and code execution. A ZoomEye query for app="Drupal" returned 436,331 assets, though that does not confirm vulnerable extensions.
- CERT-Bund advisory WID-SEC-2026-3554 covers 35 CVEs, including CVE-2026-96368
- XSS can read session cookies and CSRF tokens and hijack admin sessions
- ZoomEye: 436,331 assets matching app="Drupal" on 28 September 2026
- CERT-Bund does not map which of the 35 CVEs are XSS; vendor advisories are needed
Read next
Security