May we please get a CVE ID reserved for the fix located at https://security.drupal.org/node/184337?

Attached is the CVE entry missing the references (no known SA) and date. Will add both on the next version.

Key items:
• from 7.x-1.0 through 7.x-1.12 (inclusive)
• description is:
"Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context.This affects versions from 7.x-1.0 through (and including) 7.x-1.12."
• I put the CVSS vector string at CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N (5.1) or medium.

Comments

aangel created an issue. See original summary.

greggles’s picture

Title: Request for Simple Hierarchical Select (SHS) CVE ID » Publish for Simple Hierarchical Select (SHS) CVE-2026-4929
Status: Active » Needs work

I reserved CVE-2026-4929 - moving to needs work for the next steps.

aangel’s picture

StatusFileSize
new5.75 KB

Revised json attached with:
• both vendor advisories
• the version number was incorrect; it should have specified <7.12
• but then I think Tag1's advisory is incorrect as they are showing <=7.12

greggles’s picture

Status: Needs work » Fixed

Now published. Thanks!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.