Date: 
2026-September-02
Vulnerability: 
Cross Site Scripting
Affected versions: 
<2.4.0
CVE IDs: 
CVE-2026-84924
Description: 

This module enables you to add an extra layer of verification for user registration.

The module doesn't sufficiently filter user-supplied input before output, resulting in an unauthenticated reflected Cross-site Scripting (XSS) vulnerability.

Solution: 

Install the latest version:

If you are using the OTP Verification module for Drupal, upgrade to the latest version 8.x-2.4

Reported By: 
Coordinated By: