CVE-2014-4303
Touch theme 7.x-1.x - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter and (2) Facebook username settings.
Scores
EPSS
0.0037
EPSS Percentile
58.3%
Details
CWE
CWE-79
Status
published
Products (10)
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
n/a/n/a
Published
Jun 18, 2014
Tracked Since
Feb 18, 2026