CVE-2024-12393

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2024-003

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from 8.8.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.


We have discovered 86,312 live websites that are affected by CVE-2024-12393.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains86,312 live websites (42% of Drupal install base)
Vulnerable Versions
  • from 8.8 through 10.2.11
  • from 10.3 through 10.3.9
  • from 11 through 11.0.8
Vulnerable Versions Count163 versions ( 47% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 9, 2024
  • Updated - Dec 11, 2024

Credits

  • Jay Beaton (finder)
  • Lee Rowlands (remediation developer)
  • catch (remediation developer)
  • Mingsong (remediation developer)
  • Juraj Nemec (remediation developer)
  • Dave Long (remediation developer)
  • Benji Fisher (remediation developer)
  • Juraj Nemec (coordinator)
  • Greg Knaddison (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-12393
United States31,926 websites



Germany8,281 websites
France6,579 websites
Belgium4,278 websites
GB3,425 websites
Netherlands3,129 websites
Russia2,281 websites
Canada2,270 websites
Switzerland2,022 websites
Italy1,991 websites

Website Distribution by TLD

Number of websites using CVE-2024-12393
.com21,798 websites
.org8,657 websites
.edu5,955 websites
.de5,543 websites
.be4,376 websites
.fr3,818 websites
.nl2,890 websites
.ca1,826 websites
.ru1,796 websites
.ch1,718 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-12393

Top websites that are affected by CVE-2024-12393. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
*********.com United States***
***.gov United States***
*******.gov United States*,***
***.gov United States*,***
******.com United States*,***
*******.com United States*,***
***.org United States*,***
***.*******.edu United States*,***
****.gov United States*,***
See full domain list

FAQ

CVE-2024-12393 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Drupal
A total of 86,312 websites have been identified as vulnerable to CVE-2024-12393, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2024-12393 vulnerability.
Drupal versions up to 11.0.8 are vulnerable to CVE-2024-12393.
CVE-2024-12393 is resolved in version 11.0.8 of Drupal.