Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9024 | Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes |
Github GHSA |
GHSA-5r66-vgc7-2mm3 | Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-026 |
|
Tue, 02 Sep 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Formatter Suite Project
Formatter Suite Project formatter Suite |
|
| CPEs | cpe:2.3:a:formatter_suite_project:formatter_suite:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Formatter Suite Project
Formatter Suite Project formatter Suite |
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 31 Mar 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0. | |
| Title | Formatter Suite - Moderately critical - Cross site scripting - SA-CONTRIB-2025-026 | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-04-29T15:16:16.212Z
Reserved: 2025-03-31T21:30:25.065Z
Link: CVE-2025-31697
Updated: 2025-04-29T15:16:10.898Z
Status : Analyzed
Published: 2025-03-31T22:15:22.427
Modified: 2025-09-02T18:34:38.900
Link: CVE-2025-31697
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA