ZeroHour
Drupal Security Advisoriespublished ()ingested Drupal Security Team

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

mediumAdvisoryimportance 32
AI summary · glm-5.3-flash

Drupal issues moderately critical advisory for XSS in bundled CKEditor affecting content editors; fixed versions released, exploitation theoretical.

Drupal published SA-CORE-2026-013, rated moderately critical (13/25), covering an XSS vulnerability in the CKEditor library used for WYSIWYG editing. An attacker able to create or edit content, even without direct CKEditor access, could exploit it to target users with WYSIWYG permissions. Affected versions include Drupal core 10.5.x, 11.0.x and 11.4.x below 11.4.7, and updated releases are available. Exploitation is rated theoretical.

  • CKEditor released a security update for an XSS flaw that also impacts Drupal's WYSIWYG editing
  • Attackers who can create or edit content may target users with WYSIWYG access
  • Affected branches include 10.5.x, 11.0.x and 11.4.x below 11.4.7
Full article

Project: Drupal core Project machine name: drupal Date: 2026-September-16 Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default Vulnerability: Third-party libraries Affected versions: >=10.5.0 =11.0.0 =11.4.0 <11.4.7 Description: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal. Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG…

This source does not provide full text. Read it at drupal.org.