Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2024-13273

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.

  • Published: Jan 9, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2024-13273
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.4
  • AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Software From Fixed in
getopensocial / open_social - 12.3.8
getopensocial / open_social 12.4.0 12.4.5
getopensocial / open_social 13.0.0-alpha1 13.0.0-alpha1.x
getopensocial / open_social 13.0.0-alpha10 13.0.0-alpha10.x
getopensocial / open_social 13.0.0-alpha2 13.0.0-alpha2.x
getopensocial / open_social 13.0.0-alpha3 13.0.0-alpha3.x
getopensocial / open_social 13.0.0-alpha4 13.0.0-alpha4.x
getopensocial / open_social 13.0.0-alpha5 13.0.0-alpha5.x
getopensocial / open_social 13.0.0-alpha6 13.0.0-alpha6.x
getopensocial / open_social 13.0.0-alpha7 13.0.0-alpha7.x
getopensocial / open_social 13.0.0-alpha8 13.0.0-alpha8.x
getopensocial / open_social 13.0.0-alpha9 13.0.0-alpha9.x