VDB
Sign up
—

DRUPAL-CONTRIB-2026-019

Details

This module adds the favicons generated by `realfavicongenerator.net` to your Drupal site.

The module does not filter administrator-entered text, leading to a persistent Cross-site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer responsive favicons".

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/responsive_favicons
Introduced in: 0Fixed in: 2.0.2

Upgrade drupal/responsive_favicons to 2.0.2 or newer (ecosystem packagist:https://packages.drupal.org/8).

References