—
DRUPAL-CONTRIB-2026-117
Details
Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.
Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.
*Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.*
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/slick
Introduced in:
0 Fixed in: 2.1.0 Upgrade drupal/slick to 2.1.0 or newer (ecosystem packagist:https://packages.drupal.org/8).