Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Real-time SEO for Drupal allows Cross-Site Scripting (XSS).This issue affects Real-time SEO for Drupal: from 2.0.0 before 2.2.0.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
2.0.0 (semver) before 2.2.0
Credits
Pierre Rudloff (prudloff)
Alexander Varwijk (kingdutch)
Pierre Rudloff (prudloff)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Pierre Rudloff (prudloff), provisional member of the Drupal Security Team
Jess (xjm)
References
www.drupal.org/sa-contrib-2025-091