The Layout Builder module doesn't sufficiently sanitize block labels in certain scenarios, which can lead to a cross-site scripting (XSS) vulnerability.
This is mitigated by the fact that both the attacker and the targeted user need to be using the Layout Builder editing interface.
Install the latest version:
Drupal 11
- If you use Drupal 11.4.x, update to .
- Drupal 11.2.x and below are end-of-life and do not receive security coverage.
Drupal 10
- If you use Drupal 10.6.x, update to and
- of the Drupal Security Team
- of the Drupal Security Team
- of the Drupal Security Team
- of the Drupal Security Team
SOCIAL SHARE CARD GENERATOR