SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-16640

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Search API Autocomplete module in Drupal is vulnerable to reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This flaw could allow attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using affected versions (0.0.0 to 1.12.0) of the Search API Autocomplete should prioritize patching this vulnerability to protect their users.

CVE
CVE-2026-16640
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.