Vulnerabilities & PatchesEmerging1 src
CVE-2026-18986 - Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094
CVE ID : CVE-2026-18986
Published : Sept. 2, 2026, 12:45 p. m.
• 32 minutes ago
Description : Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. This issue affects Entity Browser versions: from 0. 0. 0 to 2. 16. 0.
Severity: 0.0
• NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...