CVE-2025-13979

Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.
References
Link Resource
https://www.drupal.org/sa-contrib-2025-117 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:salsa.digital:mini_site:*:*:*:*:*:drupal:*:*

History

No history.

Information

Published : 2026-01-28 20:16

Updated : 2026-02-12 19:50


NVD link : CVE-2025-13979

Mitre link : CVE-2025-13979

CVE.ORG link : CVE-2025-13979


JSON object : View

Products Affected

salsa.digital

  • mini_site
CWE
CWE-267

Privilege Defined With Unsafe Actions

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')