Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004
Summary
| CVE | CVE-2025-31675 |
|---|---|
| State | PUBLISHED |
| Assigner | drupal |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-03-31 22:15:20 UTC |
| Updated | 2026-04-02 23:17:04 UTC |
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5. It also affects the Drupal 7 module from versions 7.x-1.0 through 7.x-1.12. |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Drupal | Drupal Core | affected 8.0.0 10.3.14 semver | Not specified |
| CNA | Drupal | Drupal Core | affected 10.4.0 10.4.5 semver | Not specified |
| CNA | Drupal | Drupal Core | affected 11.0.0 11.0.13 semver | Not specified |
| CNA | Drupal | Drupal Core | affected 11.1.0 11.1.5 semver | Not specified |
| CNA | Drupal | Link | affected 7.x-1.0 7.x-1.12 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.herodevs.com/vulnerability-directory/cve-2025-31675 | [email protected] | www.herodevs.com | |
| d7es.tag1.com/security-advisories/link-moderately-critical-cross-site-scrip... | [email protected] | d7es.tag1.com | |
| www.drupal.org/sa-core-2025-004 | [email protected] | www.drupal.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Samuel Mortenson (samuel.mortenson) (en)
CNA: Benji Fisher (benjifisher) (en)
CNA: Bram Driesen (bramdriesen) (en)
CNA: Alex Bronstein (effulgentsia) (en)
CNA: Jen Lampton (jenlampton) (en)
CNA: Lee Rowlands (larowlan) (en)
CNA: Dave Long (longwave) (en)
CNA: Drew Webber (mcdruid) (en)
CNA: Joseph Zhao (pandaski) (en)
CNA: Adam G-H (phenaproxima) (en)
CNA: Samuel Mortenson (samuel.mortenson) (en)
CNA: Jess (xjm) (en)
There are currently no legacy QID mappings associated with this CVE.