View online: https://www.drupal.org/sa-contrib-2026-137 Project: Feed Block [1] Date: 2026-September-09 Security risk: *Moderately critical* 13 ∕ 25 AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross-site scripting Affected versions: <2.0.2 || >=3.0.0 <3.0.2 CVE IDs: CVE-2026-87939 Description: The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed. The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability. Solution: Install the latest version: * If you use the 3.x branch, upgrade to Feed Block 3.0.2 [3]. * If you use the 2.x branch, upgrade to Feed Block 2.0.2 [4]. Reported By: * Marcus Johansson (marcus_johansson) [5] Fixed By: * Greg Knaddison (greggles) [6] of the Drupal Security Team * Mark Fullmer (mark_fullmer) [7] * mmarler [8] Coordinated By: * Bram Driesen (bramdriesen) [9] of the Drupal Security Team * Greg Knaddison (greggles) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team * Swan Kalata (akalata) [13] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [14] [1] https://www.drupal.org/project/feed_block [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/feed_block/releases/3.0.2 [4] https://www.drupal.org/project/feed_block/releases/2.0.2 [5] https://www.drupal.org/u/marcus_johansson [6] https://www.drupal.org/u/greggles [7] https://www.drupal.org/u/mark_fullmer [8] https://www.drupal.org/u/mmarler [9] https://www.drupal.org/u/bramdriesen [10] https://www.drupal.org/u/greggles [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://www.drupal.org/u/akalata [14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....