CVE-2026-81160 PUBLISHED

Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

Assigner: drupal
Reserved: 26.08.2026 Published: 02.09.2026 Updated: 02.09.2026

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. This issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.

Product Status

Vendor Drupal
Product Slick Carousel
Versions
  • affected from 0.0.0 to 2.1.0 (excl.)

Credits

  • Drew Webber (mcdruid) finder
  • Gaus Surahman (gausarts) remediation developer
  • Swan Kalata (akalata) coordinator
  • cilefen coordinator
  • Neil Drumm (drumm) coordinator
  • Greg Knaddison (greggles) coordinator
  • Drew Webber (mcdruid) coordinator
  • Pierre Rudloff (prudloff) coordinator

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") CWE

Impacts

  • CAPEC-592 Stored XSS