VDB
KO

DRUPAL-CONTRIB-2026-117

Details

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.

Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.

*Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.*

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/slick
Introduced in: 0 Fixed in: 2.1.0

Upgrade drupal/slick to 2.1.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References