CVE-2025-31675 - CVE House
Back to Database
Status published Unknown CVE-2025-31675

Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2025-004

Vulnerability Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).This issue affects Drupal core: from 8.0.0 before 10.3.14, from 10.4.0 before 10.4.5, from 11.0.0 before 11.0.13, from 11.1.0 before 11.1.5. It also affects the Drupal 7 module from versions 7.x-1.0 through 7.x-1.12.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-31675

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Samuel Mortenson (samuel.mortenson)
  • Benji Fisher (benjifisher)
  • Bram Driesen (bramdriesen)
  • Alex Bronstein (effulgentsia)
  • Jen Lampton (jenlampton)
  • Lee Rowlands (larowlan)
  • Dave Long (longwave)
  • Drew Webber (mcdruid)
  • Joseph Zhao (pandaski)
  • Adam G-H (phenaproxima)
  • Samuel Mortenson (samuel.mortenson)
  • Jess (xjm)

Affected Vendor

Affected Software

Drupal core, Link
Vulnerable Versions:
8.0.0, 10.4.0, 11.0.0, 11.1.0, 7.x-1.0

Timeline

Official Publish: March 31st, 2025
Last Modified: April 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)