CVE-2026-2348: Wim-Leers Quick Edit
Medium severity, CVSS 5.4. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit allows Cross-Site Scripting (XSS).This issue affects Quick Edit: from 0.0.0 before 1.0.5, from 2.0.0 before 2.0.1.
Affected products
- Wim-Leers Quick Edit: before 1.0.5 (fixed in 1.0.5); version 2.0.0 only
Published 2026-03-25. Last modified 2026-06-17.