Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.
References
| Link | Resource |
|---|---|
| https://www.drupal.org/sa-contrib-2025-041 | Third Party Advisory |
| https://backdropcms.org/security/backdrop-sa-contrib-2025-012 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-23 17:16
Updated : 2025-06-20 16:22
NVD link : CVE-2025-3900
Mitre link : CVE-2025-3900
CVE.ORG link : CVE-2025-3900
JSON object : View
Products Affected
colorbox_project
- colorbox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
