Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11570

Опубликовано: 10 окт. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient filtering of data.

Note: This is exploitable only if the code is executed outside of Drupal; the function is intended to be shared between Drupal and Pattern Lab.

The package drupal-pattern-lab/unified-twig-extensions is unmaintained, the fix for this issue exists in version 1.1.1 of drupal/unified_twig_ext

EPSS

Процентиль: 11%
0.00039
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

github
4 месяца назад

drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS

EPSS

Процентиль: 11%
0.00039
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-79