Date: 
2026-July-22
Vulnerability: 
Cross-site Scripting
Affected versions: 
<1.12.0
CVE IDs: 
CVE-2026-16640
Description: 

This module enables you to add autocomplete suggestions for search forms created with the Search API module.

The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users.

Solution: 

Install the latest version:

Another option for sites unable to update is to set display_errors: off in php.ini (or similar settings) to disable the exploit.

Reported By: 
Coordinated By: