Executive brief
The Term Reference Tree Widget module for Drupal 7, which provides a hierarchical selection tool for organizing website content, contains security flaws that allow for stored cross-site scripting (XSS). An attacker with the ability to edit website categories (taxonomy terms) can inject malicious scripts that execute in the browsers of other users, including administrators. This could lead to unauthorized actions being performed on behalf of users, session hijacking, or the defacement of administrative interfaces.
Technical details
The Term Reference Tree module for Drupal 7 fails to properly sanitize output in two specific areas of its rendering pipeline. Vector A involves the 'token display templates' (token_display_selected/unselected); when the Token module is enabled, the widget renders token output (such as term descriptions) without proper escaping. Vector B involves term label rendering; when the widget is configured to display parent terms as labels (e.g., 'Leaves only' mode), the term names are output without safe escaping. Both vectors require the attacker to have permissions to create or edit taxonomy terms. An exploit allows for the execution of arbitrary JavaScript in the context of any user viewing the affected widget or formatter. The issue is resolved in version 7.x-1.12.
Affected products
- Drupal Term Reference Tree Widget 7.x-1.x up to and including 7.x-1.11
Timeline
- 2026-01-06: patched: Fixed in NES for Drupal 7
- 2026-04-01: advisory: Tag1 D7ES advisory published
- 2026-05-21: disclosed: CVE published to NVD