—
DRUPAL-CONTRIB-2025-083
Details
[Simple XML sitemap](https://www.drupal.org/project/simple_sitemap) is a SEO module that allows creating various XML sitemaps of the site's content and submitting them to search engines. The module doesn't sufficiently sanitize input when administering it, which leads to a Cross-site scripting (XSS) attack vector. This vulnerability is mitigated by the fact that an attacker must have the administrative permission 'administer sitemap settings'.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/simple_sitemap
Introduced in:
0Fixed in: 4.2.2Upgrade drupal/simple_sitemap to 4.2.2 or newer (ecosystem packagist:https://packages.drupal.org/8).