{"id":"DRUPAL-CONTRIB-2025-083","details":"[Simple XML sitemap](https://www.drupal.org/project/simple_sitemap) is a SEO module that allows creating various XML sitemaps of the site's content and submitting them to search engines.  \nThe module doesn't sufficiently sanitize input when administering it, which leads to a Cross-site scripting (XSS) attack vector.  \nThis vulnerability is mitigated by the fact that an attacker must have the administrative permission 'administer sitemap settings'.","aliases":["CVE-2025-6676"],"modified":"2026-09-10T03:46:13.130902744Z","published":"2025-06-25T18:42:38Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-083"}],"affected":[{"package":{"name":"drupal/simple_sitemap","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/simple_sitemap?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.2"}],"database_specific":{"constraint":"\u003c 4.2.2"}}],"database_specific":{"source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/simple_sitemap/DRUPAL-CONTRIB-2025-083.json","affected_versions":"\u003c 4.2.2"}}],"schema_version":"1.9.0","credits":[{"name":"Nick Vanpraet (grayle)","contact":["https://www.drupal.org/u/grayle"]}]}