Project: 
Date: 
2026-September-09
Vulnerability: 
Cross-site scripting
Affected versions: 
<2.0.2 || >=3.0.0 <3.0.2
CVE IDs: 
CVE-2026-87939
Description: 

The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.

The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability.

Solution: 

Install the latest version:

Fixed By: 
Coordinated By: