Executive brief
The Tagify module for Drupal, which provides an enhanced user interface for selecting tags and categories, contains a security flaw. An attacker with permission to edit website categories could inject malicious scripts that execute in the browsers of other users, potentially leading to unauthorized actions or data theft. This issue affects websites using Tagify to manage hierarchical data like taxonomy terms.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Drupal Tagify module versions 0.0.0 through 1.2.51. The vulnerability is located in the component responsible for rendering hierarchical taxonomy terms within the Tagify suggestions dropdown, where it fails to properly sanitize the names of parent terms. An attacker with the 'create' or 'edit' permission for taxonomy terms can inject malicious JavaScript into a term name. When another user interacts with the Tagify widget and triggers the suggestions dropdown, the script executes in their session context. The issue is fixed in version 1.2.52 and 2.0.2.
Affected products
- Drupal Tagify 0.0.0 to 1.2.51
Timeline
- 2026-06-10: advisory: Drupal security advisory SA-CONTRIB-2026-043 published
- 2026-06-17: patched: Fixed versions 1.2.53 and 2.0.2 released
- 2026-07-10: disclosed: CVE-2026-11908 published to NVD