Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: from 7.X-3.0 through 7.X-3.9.
References (2)
Core 2
Core References
Exploit, Third Party Advisory vendor-advisory
https://www.herodevs.com/vulnerability-directory/cve-2025-14556
Third Party Advisory vendor-advisory
https://d7es.tag1.com/security-advisories/flag-moderately-critical-cross-site-scripting-backdrop-sa-contrib-2025-011
Scores
CVSS v3
5.4
EPSS
0.0018
EPSS Percentile
7.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
flag_module_project/flag
7.x-3.0 - 7.x-3.9
Published
Jan 14, 2026
Tracked Since
Feb 18, 2026