Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m3f2-xjgc-2wp2 | Drupal JSON Field is vulnerable to XSS |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-106 |
|
Fri, 12 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Json Field Project
Json Field Project json Field |
|
| CPEs | cpe:2.3:a:json_field_project:json_field:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Json Field Project
Json Field Project json Field |
Thu, 30 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal drupal Drupal json Field |
|
| Vendors & Products |
Drupal
Drupal drupal Drupal json Field |
Wed, 29 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal JSON Field allows Cross-Site Scripting (XSS).This issue affects JSON Field: from 0.0.0 before 1.5. | |
| Title | JSON Field - Critical - Cross Site Scripting - SA-CONTRIB-2025-106 | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-10-30T14:43:55.094Z
Reserved: 2025-09-24T16:53:09.180Z
Link: CVE-2025-10926
Updated: 2025-10-30T14:43:39.281Z
Status : Analyzed
Published: 2025-10-30T00:15:33.003
Modified: 2025-12-12T18:00:04.623
Link: CVE-2025-10926
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:37:35Z
Github GHSA