Headline
GHSA-pr6m-qwrr-mrw9: Drupal Plausible tracking is vulnerable to XSS
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in Drupal Plausible tracking allows Cross-Site Scripting (XSS). This issue affects Plausible tracking: from 0.0.0 before 1.0.2.
Skip to content
Navigation Menu
- AI CODE CREATION - GitHub CopilotWrite better code with AI 
- GitHub SparkBuild and deploy intelligent apps 
- GitHub ModelsManage and compare prompts 
- MCP RegistryNewDiscover and integrate external tools 
 
 
View all features
- Pricing
Provide feedback
Saved searches****Use saved searches to filter your results more quickly
Sign up
Appearance settings
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2025-10927
Drupal Plausible tracking is vulnerable to XSS
Moderate severity GitHub Reviewed Published Oct 30, 2025 to the GitHub Advisory Database • Updated Oct 30, 2025
Package
composer drupal/plausible_tracking (Composer)
Affected versions
< 1.0.2
Description
Published to the GitHub Advisory Database
Oct 30, 2025
Last updated
Oct 30, 2025
EPSS score