CVE-2010-2048
Menhir Heartbeat - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
References (5)
Scores
EPSS
0.0021
EPSS Percentile
42.8%
Classification
CWE
CWE-79
Status
published
Affected Products (20)
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
menhir/heartbeat
... and 5 more
Timeline
Published
May 25, 2010
Tracked Since
Feb 18, 2026