Project machine name: 
inline_formatter_field
Date: 
2026-October-07
Vulnerability: 
Server-side template injection
Affected versions: 
<4.2.0
CVE IDs: 
CVE-2026-107264
Description: 

The Inline Formatter Field module allows site builders to template and style entities with a field.

This module does not properly protect against template injection when parsing, allowing users to render protected data or execute unsafe Twig commands.

Solution: 

Install the latest version:

Coordinated By: