This affects versions from 7.x-1.0 through (and including) 7.x-1.10.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simple Hierarchical Select Project
Simple Hierarchical Select Project simple Hierarchical Select |
|
| CPEs | cpe:2.3:a:simple_hierarchical_select_project:simple_hierarchical_select:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Simple Hierarchical Select Project
Simple Hierarchical Select Project simple Hierarchical Select |
|
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 22 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal simple Hierarchical Select (shs) |
|
| Vendors & Products |
Drupal
Drupal simple Hierarchical Select (shs) |
Fri, 22 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 21 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context. This affects versions from 7.x-1.0 through (and including) 7.x-1.10. | |
| Title | Simple Hierarchical Select (Drupal 7) XSS in term-derived output | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-05-22T12:52:46.535Z
Reserved: 2026-03-26T19:18:14.271Z
Link: CVE-2026-4929
Updated: 2026-05-22T12:52:08.555Z
Status : Analyzed
Published: 2026-05-21T22:16:48.420
Modified: 2026-06-17T10:57:28.383
Link: CVE-2026-4929
No data.
OpenCVE Enrichment
Updated: 2026-05-22T12:38:25Z