CVE-2026-81201: Monster Menus Project Monster Menus

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

Affected products

  • Monster Menus Project Monster Menus: from 6.x-6.19, up to and including 6.x-6.64; from 7.x-1.0, up to and including 7.x-1.34; from 9.0.0, before 9.5.3 (fixed in 9.5.3)

Published 2026-09-02. Last modified 2026-09-16.