Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.

Project Subscriptions

Vendors Products
Bordeaux-metropole Subscribe
At Internet Smarttag Subscribe
At Internet Smarttag Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Wed, 11 Feb 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Bordeaux-metropole
Bordeaux-metropole at Internet Smarttag
CPEs cpe:2.3:a:bordeaux-metropole:at_internet_smarttag:*:*:*:*:*:drupal:*:*
Vendors & Products Bordeaux-metropole
Bordeaux-metropole at Internet Smarttag

Fri, 06 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal at Internet Smarttag
Vendors & Products Drupal
Drupal at Internet Smarttag

Wed, 04 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1.
Title AT Internet SmartTag - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-003
Weaknesses CWE-79
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-02-06T20:35:38.434Z

Reserved: 2026-01-14T16:52:30.774Z

Link: CVE-2026-0946

cve-icon Vulnrichment

Updated: 2026-02-06T20:35:34.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-04T21:15:58.907

Modified: 2026-02-11T19:19:34.760

Link: CVE-2026-0946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-05T11:39:50Z

Weaknesses