View online: https://www.drupal.org/sa-contrib-2026-014
Project: Anti-Spam by CleanTalk [1] Date: 2026-February-25 Security risk: *Moderately critical* 13 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Cross-site scripting
Affected versions: <9.7.0 CVE IDs: CVE-2026-3213 Description: This module enables you to block bots by Firewall.
The module doesn't sufficiently sanitize user input leading to a reflected Cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that the vulnerable functionality is only presented to users that are "challenged" or blocked by the firewall.
Solution: Install the latest version:
* If you use the Anti-Spam by CleanTalk module for Drupal, upgrade to Anti-Spam by CleanTalk 9.7.0 [3].
Reported By: * Drew Webber (mcdruid) [4] of the Drupal Security Team
Fixed By: * glomberg [5] * Drew Webber (mcdruid) [6] of the Drupal Security Team * sergefcleantalk [7]
Coordinated By: * Damien McKenna (damienmckenna) [8] of the Drupal Security Team * Greg Knaddison (greggles) [9] of the Drupal Security Team * Drew Webber (mcdruid) [10] of the Drupal Security Team * Juraj Nemec (poker10) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team
------------------------------------------------------------------------------ Contribution record [13]
[1] https://www.drupal.org/project/cleantalk [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/cleantalk/releases/9.7.0 [4] https://www.drupal.org/u/mcdruid [5] https://www.drupal.org/u/glomberg [6] https://www.drupal.org/u/mcdruid [7] https://www.drupal.org/u/sergefcleantalk [8] https://www.drupal.org/u/damienmckenna [9] https://www.drupal.org/u/greggles [10] https://www.drupal.org/u/mcdruid [11] https://www.drupal.org/u/poker10 [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....