May we please get a CVE ID reserved for the fix located at https://security.drupal.org/node/184337?
Attached is the CVE entry missing the references (no known SA) and date. Will add both on the next version.
Key items:
• from 7.x-1.0 through 7.x-1.12 (inclusive)
• description is:
"Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context.This affects versions from 7.x-1.0 through (and including) 7.x-1.12."
• I put the CVSS vector string at CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N (5.1) or medium.
| Comment | File | Size | Author |
|---|---|---|---|
| #3 | CVE-2026-4929-shs.json_.txt | 5.75 KB | aangel |
| CVE-2026-shs-xss.json_.txt | 4.24 KB | aangel |
Comments
Comment #2
gregglesI reserved CVE-2026-4929 - moving to needs work for the next steps.
Comment #3
aangel commentedRevised json attached with:
• both vendor advisories
• the version number was incorrect; it should have specified <7.12
• but then I think Tag1's advisory is incorrect as they are showing <=7.12
Comment #4
gregglesNow published. Thanks!