Junglewise Threat Intelligence

CVE-2026-3212: DRUPAL-CONTRIB-2026-013 - This module integrates the Tagify JavaScript library to enhance taxonomy entity reference widgets. The module does not sufficiently sanitis

CVE-2026-3212 · Severity: info · Published 2026-02-25

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Tagify. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module integrates the Tagify JavaScript library to enhance taxonomy entity reference widgets.

The module does not sufficiently sanitise user-supplied input before rendering it inside JavaScript template strings within the Tagify widget. This allows arbitrary JavaScript execution in the browser when a user creates or edits content.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/tagify

Related threats