CVE-2010-3094

Drupal 6.x <6.18 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action description, (2) an action message, (3) a node, or (4) a taxonomy term, related to the actions feature and the trigger module.

Scores

EPSS 0.0022
EPSS Percentile 44.2%

Classification

CWE
CWE-79
Status published

Affected Products (29)

drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
drupal/drupal
... and 14 more

Timeline

Published Sep 21, 2010
Tracked Since Feb 18, 2026