Project:
Date:
2025-September-24
Vulnerability:
Cross Site Scripting
Affected versions:
<1.5
CVE IDs:
CVE-2025-10926
Description:
This module enables you to store and display JSON data using optional 3rd party libraries.
The module doesn't sufficiently filter data using some of the included field formatters leading to a Cross-site Scripting (XSS) vulnerability.
Solution:
Install the latest version:
- If you use the JSON Field module for Drupal 8.x, upgrade to JSON Field 8.x-1.5.
Reported By:
Fixed By:
- Ivan (chi)
- Damien McKenna (damienmckenna) of the Drupal Security Team
Coordinated By:
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team