Junglewise Threat Intelligence

CVE-2026-13231: Drupal Advanced Content Feedback stored XSS in response messages

CVE-2026-13231 · Severity: info · CVSS 5.4 · Published 2026-07-10

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Advanced Content Feedback module for Drupal, which allows website visitors to provide feedback on content, contains a security flaw. An authorized administrator could configure the module with malicious scripts that would then execute in the browsers of regular site visitors. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Drupal Advanced Content Feedback (admin_feedback) module versions prior to 2.8.0. The module fails to sanitize several administrator-configurable fields, including the 'Yes response', 'No response', and custom 'No' answer text. An attacker with the 'administer admin feedback' permission can inject malicious HTML or JavaScript into these settings. When a site visitor interacts with the feedback block, the malicious payload is rendered as raw HTML in their browser. The issue was resolved in version 2.8.0 by implementing proper escaping and text format filtering.

Affected products

  • Drupal Advanced Content Feedback (admin_feedback) >= 0.0.0, < 2.8.0

Timeline

  • 2026-06-24: patched: Security advisory SA-CONTRIB-2026-051 and version 2.8.0 released.
  • 2026-07-10: disclosed: CVE-2026-13231 published.

References

Related threats