# Drupal patches XSS flaws in core

Published: 2026-09-17 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/8646dd2d-cdbb-5691-bd7f-cbc3603a0ba4/drupal-patches-xss-flaws-in-core

> CERT-FR advisory details multiple XSS vulnerabilities in Drupal core affecting versions before 11.4.7, 11.3.17, and 10.6.17.

CERT-FR published an advisory summarizing a Drupal security bulletin (SA-CORE-2026-013) describing multiple cross-site scripting (XSS) vulnerabilities in Drupal core. The flaws allow an attacker to achieve indirect remote code injection via XSS, potentially enabling script execution in the context of a victim's browser session on affected Drupal sites.

Affected versions include Drupal 11.4.x prior to 11.4.7, Drupal 11.x prior to 11.3.17, and all Drupal versions prior to 10.6.17. No indication of active exploitation is mentioned in the advisory. Defenders running Drupal should apply the vendor's patches referenced in the official Drupal security bulletin as soon as possible to remediate the identified XSS issues.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1196

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/8646dd2d-cdbb-5691-bd7f-cbc3603a0ba4/drupal-patches-xss-flaws-in-core.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
