VDB
KO

DRUPAL-CONTRIB-2026-103

Details

The Address Suggestion module provides address autocomplete functionality using configured address providers.

The module doesn't sufficiently sanitize address suggestion data returned by configured providers, which can lead to a cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to inject malicious content into data returned by a configured address provider, and a user must perform a search that returns the malicious suggestion.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/address_suggestion
Introduced in: 0 Fixed in: 1.0.25

Upgrade drupal/address_suggestion to 1.0.25 or newer (ecosystem packagist:https://packages.drupal.org/8).

References