VDB
Sign up
—

DRUPAL-CONTRIB-2025-084

Details

Project Paragraphs table provides a field for a collection table.

The module doesn't sufficiently sanitise certain data attributes allowing Cross Site Scripting (XSS) attacks.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/paragraphs_table
Introduced in: 2.0.0Fixed in: 2.0.5

Upgrade drupal/paragraphs_table to 2.0.5 or newer (ecosystem packagist:https://packages.drupal.org/8).

References