Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.44.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")
Product status
0.0.0 (semver) before 1.2.44
Credits
Drew Webber (mcdruid)
Bram Driesen (bramdriesen)
David Galeano (gxleano)
Lee Rowlands (larowlan)
Drew Webber (mcdruid)
Bram Driesen (bramdriesen)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-121