CVE-2026-6367 | Drupal up to 11.3.6 cross site scripting (sa-core-2026-003)
A vulnerability, which was classified as problematic, was found in Drupal up to 11.3.6. This impacts an unknown function. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-6367. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.