CVE-2026-3529: Sujanshrestha Google Analytics GA4
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Google Analytics GA4 allows Cross-Site Scripting (XSS).This issue affects Google Analytics GA4: from 0.0.0 before 1.1.14.
Affected products
- Sujanshrestha Google Analytics GA4: before 1.1.14 (fixed in 1.1.14)
Published 2026-03-26. Last modified 2026-06-17.