Junglewise Threat Intelligence

CVE-2026-15084: Drupal UI Patterns stored XSS in SDC components

CVE-2026-15084 · Severity: info · CVSS 6.4 · Published 2026-07-10

Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Drupal UI Patterns module, which helps site builders create reusable design components, contains a security flaw that fails to properly clean data before displaying it. An attacker with the ability to create or edit content on the site could use this to inject malicious scripts that run in the browsers of other users. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Drupal UI Patterns module (specifically the SDC integration) due to improper neutralization of input during web page generation. The module fails to sufficiently sanitize markup passed to components in certain scenarios. An attacker with permissions to create or update content rendered by UI Patterns can inject malicious scripts that execute in the context of other users' browsers. The issue affects versions 2.0.0 through 2.0.16 and is fixed in version 2.0.17.

Affected products

  • Drupal UI Patterns (SDC in Drupal UI) 2.0.0 to 2.0.16

Timeline

  • 2026-07-08: patched: Version 2.0.17 released
  • 2026-07-08: advisory: Drupal security advisory SA-CONTRIB-2026-075 published
  • 2026-07-10: disclosed: CVE-2026-15084 published

References