60
A “highly critical” flaw affects Drupal 7 and 8 core, Drupal security updates expected on March 28th
55
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013
Drupal issues moderately critical advisory for XSS in bundled CKEditor affecting content editors; fixed versions released, exploitation theoretical.
Drupal published SA-CORE-2026-013, rated moderately critical (13/25), covering an XSS vulnerability in the CKEditor library used for WYSIWYG editing. An attacker able to create or edit content, even without direct CKEditor access, could exploit it to target users with WYSIWYG permissions. Affected versions include Drupal core 10.5.x, 11.0.x and 11.4.x below 11.4.7, and updated releases are available. Exploitation is rated theoretical.
32
60
60
55
60
60
35
60
55
60
30
60
55
60
60
60
60
60
60
60
60
60
60
60
60
60
60
60
60
60
60
47
60
60
60
60
60
60