Junglewise Threat Intelligence

CVE-2026-4929: Drupal Simple Hierarchical Select XSS in taxonomy term names

CVE-2026-4929 · Severity: info · CVSS 5.1 · Published 2026-05-21

Vendors: Drupal.

Executive brief

The Simple Hierarchical Select (SHS) module for Drupal 7, which provides nested dropdown menus for categorizing content, contains a security flaw that allows for cross-site scripting (XSS). An attacker with permissions to create or edit category terms could inject malicious scripts that execute in the browsers of other users or administrators. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Simple Hierarchical Select (SHS) module for Drupal 7 due to insufficient sanitization of taxonomy term names. The vulnerability manifests in two primary locations: the field formatter output (shs_field_formatter_view) when 'Link to term page' is disabled, and the AJAX response for child-term data generation (shs_term_get_children). An attacker with 'edit taxonomy' permissions can inject malicious HTML/JavaScript into a term name, which is then rendered unsafely in the browser of users interacting with the SHS widget or viewing content tagged with the malicious term. The issue is fixed in version 7.x-1.12.

Affected products

  • Drupal Simple Hierarchical Select (SHS) 7.x-1.0 through 7.x-1.10

Timeline

  • 2026-03-03: patched: Fixed in NES for Drupal 7
  • 2026-03-04: advisory: Tag1 D7ES advisory published
  • 2026-05-21: disclosed: CVE published to NVD

References