Project: 
Date: 
2026-August-05
Vulnerability: 
Cross site scripting
Affected versions: 
<2.16.0
CVE IDs: 
CVE-2026-18986
Description: 

The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.

The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.

The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: