Project:
Project machine name:
css_usage_analyzerDate:
2026-September-23
Vulnerability:
Improper access control
Affected versions:
>=1.0.0 <1.0.2
CVE IDs:
CVE-2026-96380
Description:
This module lets a frontend scanner post CSS-usage measurements to the site so admin reports can show real-page statistics.
This module doesn't sufficiently protect the /css-usage-analyzer/save endpoint against forged or repeated submissions.
Solution:
Install the latest version:
- Upgrade to CSS Usage Analyzer 1.0.2.
Reported By:
Fixed By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Marcus Johansson (marcus_johansson)
- Zeeshaan khann (zeeshan_khan)
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team