—
DRUPAL-CONTRIB-2026-036
Details
This module enables you to open content already on the page within a colorbox.
The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/colorbox_inline
Introduced in:
0Fixed in: 2.1.1Upgrade drupal/colorbox_inline to 2.1.1 or newer (ecosystem packagist:https://packages.drupal.org/8).