Project: 
Date: 
2026-August-26
Vulnerability: 
Cross Site Scripting
Affected versions: 
<2.1.0
CVE IDs: 
CVE-2026-81160
Description: 

Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.

Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.

Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.

Solution: 
  • Only the 3.0.x branch is supported by the maintainers. Upgrade to a release on that branch.
Reported By: 
Coordinated By: