CVE-2008-3097

Tinytax <5.x-1.10-1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term.

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

drupal/tinytax_taxonomy_block_module

Timeline

Published Jul 09, 2008
Tracked Since Feb 18, 2026