Project: 
Date: 
2026-February-11
Vulnerability: 
Cross-site Scripting
Affected versions: 
<1.0.5 || >=2.0.0 <2.0.1
CVE IDs: 
CVE-2026-2348
Description: 

This module allows content to be edited in-place.

The module doesn't sufficiently sanitize certain image-related values during the editing process leading to a persistent Cross-site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit an affected field.

Solution: 

Install the latest version:

  • If you use the QuickEdit module, upgrade to 2.0.1 or 1.0.5
Reported By: 
Coordinated By: