CVE-2026-4093

In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:taxonomy_term_reference_tree_widget_project:taxonomy_term_reference_tree_widget:*:*:*:*:*:drupal:*:*

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) En el módulo Drupal 7 Term Reference Tree, existen dos vectores de XSS almacenado en la cadena de renderizado de widgets/formatters. Vector A (plantillas de visualización de tokens): Cuando el módulo Token está habilitado y las plantillas de visualización de tokens están configuradas, la salida de token controlada por el atacante (p. ej., descripción del término) se renderiza sin la sanitización adecuada. Cualquier usuario que pueda editar los términos de taxonomía referenciados puede inyectar HTML/JS que se ejecuta cuando se renderiza el campo. Vector B (renderizado de etiquetas de término): Las etiquetas de los términos de taxonomía no se sanitizan correctamente antes de ser renderizadas en el widget, lo que permite a un usuario con permiso para crear o editar términos de taxonomía inyectar scripts en el nombre del término que se ejecutan cuando se visualiza un formulario que contiene el widget. El exploit afecta a las versiones 7.x-1.x hasta la 7.x-1.11 inclusive.

01 Jun 2026, 17:39

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://d7es.tag1.com/security-advisories/taxonomy-term-reference-tree-widget-moderately-critical-cross-site-scripting - () https://d7es.tag1.com/security-advisories/taxonomy-term-reference-tree-widget-moderately-critical-cross-site-scripting - Third Party Advisory
References () https://www.herodevs.com/vulnerability-directory/cve-2026-4093 - () https://www.herodevs.com/vulnerability-directory/cve-2026-4093 - Exploit, Third Party Advisory
First Time Taxonomy Term Reference Tree Widget Project taxonomy Term Reference Tree Widget
Taxonomy Term Reference Tree Widget Project
CPE cpe:2.3:a:taxonomy_term_reference_tree_widget_project:taxonomy_term_reference_tree_widget:*:*:*:*:*:drupal:*:*

21 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 22:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-4093

Mitre link : CVE-2026-4093

CVE.ORG link : CVE-2026-4093


JSON object : View

Products Affected

taxonomy_term_reference_tree_widget_project

  • taxonomy_term_reference_tree_widget
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')