VDB
KO

DRUPAL-CONTRIB-2026-094

Details

The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.

The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/entity_browser
Introduced in: 0 Fixed in: 2.16.0

Upgrade drupal/entity_browser to 2.16.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References