Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered.
Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed.
Exploit affects versions 7.x-1.x up to and including 7.x-1.11.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Taxonomy Term Reference Tree Widget Project
Taxonomy Term Reference Tree Widget Project taxonomy Term Reference Tree Widget |
|
| CPEs | cpe:2.3:a:taxonomy_term_reference_tree_widget_project:taxonomy_term_reference_tree_widget:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Taxonomy Term Reference Tree Widget Project
Taxonomy Term Reference Tree Widget Project taxonomy Term Reference Tree Widget |
|
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal term Reference Tree |
|
| Vendors & Products |
Drupal
Drupal term Reference Tree |
Thu, 21 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11. | |
| Title | Stored XSS in Drupal 7 Term Reference Tree module (token display templates and term labels) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-05-22T13:24:04.565Z
Reserved: 2026-03-12T22:40:32.279Z
Link: CVE-2026-4093
Updated: 2026-05-22T13:23:59.499Z
Status : Analyzed
Published: 2026-05-21T22:16:48.290
Modified: 2026-06-17T10:55:58.913
Link: CVE-2026-4093
No data.
OpenCVE Enrichment
Updated: 2026-05-22T12:38:24Z