CVE-2026-4929 Details
Description
Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_field_formatter_view) and term-tree child-term data generation (shs_term_get_children). Malicious taxonomy term names can be rendered unsafely depending on output context. This affects versions from 7.x-1.0 through (and including) 7.x-1.10.
A cross-site scripting (XSS) vulnerability has been identified in the Simple Hierarchical Select (SHS) module for Drupal 7, specifically in versions 7.x-1.0 prior to 7.x-1.12. The issue arises from improper output escaping of term-derived text, allowing malicious taxonomy term names to be rendered unsafely depending on the output context. This vulnerability affects the SHS field formatter output and the term-tree child-term data generation, where unsanitized HTML content in term names could be executed in a user's browser.
Users should upgrade to Simple Hierarchical Select version 7.x-1.12 or later. HeroDevs customers can access the patched version immediately.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.herodevs.com/vulnerability-directory/cve-2026-4929?nes-for-drupal-7 | CISA-ADP | ExploitThird Party Advisory |
| https://d7es.tag1.com/security-advisories/simple-hierarchical-select-moderately-critical-cross-site-scripting | [email protected] | Third Party Advisory |
| https://www.herodevs.com/vulnerability-directory/cve-2026-4929 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| simple hierarchical select project simple hierarchical select | >= 7.x-1.0, <= 7.x-1.10 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 22, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | New CVE Received | [email protected] |