CVE-2026-4093 Details
Description
In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Vector A (token display templates): When the Token module is enabled and token display templates are configured, attacker-controlled token output (e.g., term description) is rendered without proper sanitization. Any user who can edit the referenced taxonomy terms can inject HTML/JS that executes when the field is rendered. Vector B (term label rendering): Taxonomy term labels are not properly sanitized before being rendered in the widget, allowing a user with permission to create or edit taxonomy terms to inject scripts into the term name that execute when a form containing the widget is viewed. Exploit affects versions 7.x-1.x up to and including 7.x-1.11.
A stored cross-site scripting vulnerability has been identified in the Drupal 7 Term Reference Tree module, specifically in versions 7.x-1.x prior to 7.x-1.12. The issue arises in the widget and formatter rendering pipeline, where attacker-controlled token output and term labels are not properly sanitized before being displayed. This allows users with permission to edit taxonomy terms to inject malicious HTML or JavaScript that executes when the content is rendered.
Users should upgrade to Term Reference Tree Widget version 7.x-1.12. Those on the HeroDevs Never-Ending Support plan can access this patched version immediately.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://d7es.tag1.com/security-advisories/taxonomy-term-reference-tree-widget-moderately-critical-cross-site-scripting | [email protected] | Third Party Advisory |
| https://www.herodevs.com/vulnerability-directory/cve-2026-4093 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| taxonomy term reference tree widget project taxonomy term reference tree widget | >= 7.x-1.0, < 7.x-1.12 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | New CVE Received | [email protected] |