VDB
Sign up
—

DRUPAL-CONTRIB-2026-036

Details

This module enables you to open content already on the page within a colorbox.

The module doesn't sufficiently sanitize the data-colorbox-inline attribute value before passing it to jQuery, leading to a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/colorbox_inline
Introduced in: 0Fixed in: 2.1.1

Upgrade drupal/colorbox_inline to 2.1.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References