CVE-2026-15917

Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.


We have discovered 4,283 live websites that are affected by CVE-2026-15917.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains4,283 live websites (2.11% of Drupal install base)
Vulnerable Versions
  • from 11.3 through 11.3.14
  • from 11.4 through 11.4.4
Vulnerable Versions Count18 versions ( 5.20% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • Pierre Rudloff (prudloff) (finder)
  • Shawn Duncan (fathershawn) (remediation developer)
  • Pierre Rudloff (prudloff) (remediation developer)
  • catch (catch) (coordinator)
  • Lee Rowlands (larowlan) (coordinator)
  • Dave Long (longwave) (coordinator)
  • Jess (xjm) (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-15917
United States1,474 websites



Denmark741 websites
France336 websites
Germany219 websites
Belgium189 websites
Switzerland127 websites
Netherlands112 websites
GB108 websites
Canada95 websites
Spain79 websites

Website Distribution by TLD

Number of websites using CVE-2026-15917
.com859 websites
.dk714 websites
.org630 websites
.fr196 websites
.be190 websites
.edu163 websites
.de146 websites
.ch108 websites
.nl90 websites
.ca87 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15917

Top websites that are affected by CVE-2026-15917. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.gov United States*,***
******.gov United States*,***
*****.gov United States*,***
*************.org United States*,***
****.************.com United States*,***
*****.fr France*,***
****************.com United States**,***
****.*******.edu United States**,***
********.***.uk United States**,***
**************.com United States**,***
See full domain list

FAQ

CVE-2026-15917 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Drupal
A total of 4,283 websites have been identified as vulnerable to CVE-2026-15917, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2026-15917 vulnerability.
Drupal versions up to 11.4.4 are vulnerable to CVE-2026-15917.
CVE-2026-15917 is resolved in version 11.4.4 of Drupal.