Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117

Project: Slick CarouselDate: 2026-August-26Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: <2.1.0CVE IDs: CVE-2026-81160Description: Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.
Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.
Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.Solution: 

  • Only the 3.0.x branch is supported by the maintainers. Upgrade to a release on that branch.

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2026-117