CVE-2008-6533
Drupal - XSS
Title source: ruleDescription
Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
References (8)
Scores
EPSS
0.0038
EPSS Percentile
59.2%
Classification
CWE
CWE-79
Status
published
Affected Products (21)
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 6 more
Timeline
Published
Mar 26, 2009
Tracked Since
Feb 18, 2026