Executive brief
Drupal's Slick Carousel module contains a stored cross-site scripting vulnerability in its UI sub-module, which allows administrators to configure carousel option sets with HTML button content. Insufficient input validation enables attackers with admin access to inject malicious scripts that execute in the browsers of all site visitors, potentially compromising user data or site functionality.
Technical details
The vulnerability is a stored XSS flaw in Slick UI (a sub-module of Slick Carousel) that fails to properly sanitize user input when processing HTML content in carousel button configurations. The root cause is insufficient input validation in option set forms prior to version 2.1.0. An authenticated administrator can inject malicious JavaScript into carousel option settings, which is then stored in the database and executed in the context of every visitor's browser. The attack requires admin-level privileges but persists across all site visitors. The vulnerability was fixed in version 8.x-2.1 (though not initially marked as a security release) and only the 3.0.x branch is currently supported for new deployments.
Affected products
- Drupal Slick Carousel 0.0.0 to 2.1.0
Timeline
- 2026-08-26: advisory: SA-CONTRIB-2026-117 published
- 2026-09-02: disclosed: CVE-2026-81160 published on NVD