CVE-2014-9346

low
Published 2014-12-08 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2386615

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/node/2385933

Application impact

VendorProductVersionsFixed
hierarchical_select_projecthierarchical_select6.x-3.0
hierarchical_select_projecthierarchical_select6.x-3.1
hierarchical_select_projecthierarchical_select6.x-3.2
hierarchical_select_projecthierarchical_select6.x-3.3
hierarchical_select_projecthierarchical_select6.x-3.4
hierarchical_select_projecthierarchical_select6.x-3.5
hierarchical_select_projecthierarchical_select6.x-3.6
hierarchical_select_projecthierarchical_select6.x-3.7
hierarchical_select_projecthierarchical_select6.x-3.8
hierarchical_select_projecthierarchical_select6.x-3.x

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.