Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allows Cross-Site Scripting (XSS).This issue affects Tagify: from 0.0.0 before 1.2.49.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")
Product status
0.0.0 (semver) before 1.2.49
Credits
David López (akalam)
Mingsong (mingsong)
David López (akalam)
David Galeano (gxleano)
Mingsong (mingsong)
Damien McKenna (damienmckenna)
Dan Smith (galooph)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Jess (xjm)
References
www.drupal.org/sa-contrib-2026-013