CVE-2010-3094
Drupal 6.x <6.18 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.
References (5)
Scores
EPSS
0.0022
EPSS Percentile
44.2%
Classification
CWE
CWE-79
Status
published
Affected Products (29)
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 14 more
Timeline
Published
Sep 21, 2010
Tracked Since
Feb 18, 2026