Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
935 articles · 105089 vulns · 39/41 feeds (7d)
← Back to list
—
CVE-2026-3528
Drupal · Calculation Fields

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields:

Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Calculation Fields allows Cross-Site Scripting (XSS).This issue affects Calculation Fields: from 0.0.0 before 1.0.4.

Affected Products

VendorProductVersions
DrupalCalculation Fields1.0.3

References

  • https://www.drupal.org/sa-contrib-2026-023

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-3528 | Calculation Fields up to 1.0.3 on Drupal cross site scripting (sa-contrib-2026-023)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-79
Published3/26/2026
Last enriched27m agov2
Trending Score20
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v2
Last enriched 27m ago
v2Tier C27m ago

Updated vendor to Drupal, product to Calculation Fields, added affected version 1.0.3, changed severity to HIGH, and updated patch available to version 1.0.4.

vendorproductaffectedVersionspatchAvailable
via VulDB
v12h ago

Initial creation