CVE-2014-5169: Date Project Date

Low severity, CVSS 3.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.

Affected products

Published 2014-10-20. Last modified 2026-06-17.