Update: CVE-2025-14556 - XSS in Drupal 7 Flag Module

Update: CVE-2025-14556 - XSS in Drupal 7 Flag Module

CVE ID : CVE-2025-14556 Published : Jan. 14, 2026, 7:16 p.m. | 28 minutes ago Description : Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: from 7.X-3.0 through 7.X-3.9. Severity: 4.8 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Jan. 14, 2026
Affected Product: Drupal
Impact: XSS

Source: Telegram CVE Monitor