View online: https://www.drupal.org/sa-contrib-2026-082 Project: Search API Autocomplete [1] Date: 2026-July-22 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:None/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Cross-site Scripting Affected versions: <1.12.0 CVE IDs: CVE-2026-16640 Description: This module enables you to add autocomplete suggestions for search forms created with the Search API module [3]. The module ships with a test script that is accessible to anonymous users and doesn't sufficiently validate user input, leading to a Cross Site Scripting vulnerability. This vulnerability is mitigated by the fact that the web server must be configured to display warning messages to users. Solution: Install the latest version: * If you use the Serach API Autocomplete module, upgrade to Serach API Autocomplete 8.x-1.12 [4] Another option for sites unable to update is to set display_errors: off in php.ini (or similar settings) to disable the exploit. Reported By: * Elar Lang (elarlang) [5] Fixed By: * Thomas Seiber (drunken monkey) [6] * Elar Lang (elarlang) [7] Coordinated By: * Greg Knaddison (greggles) [8] of the Drupal Security Team * Lee Rowlands (larowlan) [9] of the Drupal Security Team * Drew Webber (mcdruid) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/search_api_autocomplete [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/search_api [4] https://www.drupal.org/project/search_api_autocomplete/releases/8.x-1.12 [5] https://www.drupal.org/u/elarlang [6] https://www.drupal.org/u/drunken-monkey [7] https://www.drupal.org/u/elarlang [8] https://www.drupal.org/u/greggles [9] https://www.drupal.org/u/larowlan [10] https://www.drupal.org/u/mcdruid [11] https://www.drupal.org/u/poker10 [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....