CVE Feed

    Dashboard / CVE / CVE-2026-4093

    CVE-2026-4093

    In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11.

    Published:May 21, 2026
    Last Modified:Jun 1, 2026
    EPS:May 21, 2026
    EPSS Score:0.00052
    CVSS Score:5.4

    Affected Products

    Vendor
    Drupal
    Product
    Term Reference Tree
    Vendor
    Taxonomy Term Reference Tree Widget Project
    Product
    Taxonomy Term Reference Tree Widget

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High