# Drupal patches XSS and data exposure flaws

Published: 2026-07-16 · Severity: medium
Canonical: https://vorant.io/reports/12cf676d-d25e-5801-9cc9-dc153f6ef85a/drupal-patches-xss-and-data-exposure-flaws

> ANSSI advises multiple Drupal core vulnerabilities allow XSS and confidentiality breaches; patches available for versions before 10.6.13, 11.3.14, and 11.4.4.

The French national cybersecurity agency (ANSSI) issued an advisory covering multiple vulnerabilities in Drupal core affecting versions prior to 10.6.13, 11.x before 11.3.14, and 11.4.x before 11.4.4. The flaws, tracked as CVE-2026-15916, CVE-2026-15917, and CVE-2026-55805, could allow an attacker to compromise data confidentiality and conduct indirect remote code injection via cross-site scripting (XSS).

Drupal published three corresponding security advisories (SA-CORE-2026-010, -011, -012) on 15 July 2026 detailing the issues and remediation. No indication of active exploitation is provided in the advisory; organizations running affected Drupal versions should apply the vendor's patches as described in the referenced bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-15916, CVE-2026-15917, CVE-2026-55805

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0889

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/12cf676d-d25e-5801-9cc9-dc153f6ef85a/drupal-patches-xss-and-data-exposure-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
