—
DRUPAL-CONTRIB-2025-107
Details
This module integrates Plausible Analytics on a site.
The module did not properly filter output in certain cases.
This vulnerability is mitigated by the fact that an attacker must have permission to add raw HTML to the website, such as an unfiltered WYSIWYG field on a public-facing comment.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/plausible_tracking
Introduced in:
0Fixed in: 1.0.2Upgrade drupal/plausible_tracking to 1.0.2 or newer (ecosystem packagist:https://packages.drupal.org/8).