CVE-2025-13979

Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.
References
Link Resource
https://www.drupal.org/sa-contrib-2025-117 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:salsa.digital:mini_site:*:*:*:*:*:drupal:*:*

History

12 Feb 2026, 19:50

Type Values Removed Values Added
First Time Salsa.digital mini Site
Salsa.digital
CWE CWE-79
CPE cpe:2.3:a:salsa.digital:mini_site:*:*:*:*:*:drupal:*:*
References () https://www.drupal.org/sa-contrib-2025-117 - () https://www.drupal.org/sa-contrib-2025-117 - Vendor Advisory

29 Jan 2026, 18:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

28 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 20:16

Updated : 2026-02-12 19:50


NVD link : CVE-2025-13979

Mitre link : CVE-2025-13979

CVE.ORG link : CVE-2025-13979


JSON object : View

Products Affected

salsa.digital

  • mini_site
CWE
CWE-267

Privilege Defined With Unsafe Actions

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')