Description The wrapper extensions do not correctly validate inputs, leading to XSS vectors. Remediation References CVE-2024-26279 Related Vulnerabilities Drupal Core 8.7.x Cross-Site Scripting (8.7.0 - 8.7.11) ownCloud Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-2042) Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-17824) MySQL CVE-2022-21331 Vulnerability (CVE-2022-21331) Play Framework Out-of-bounds Write Vulnerability (CVE-2020-27196) Severity Medium Classification CVE-2024-26279 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities