Slick Carousel - Moderately critical - Cross Site Scripting - SA-CONTRIB-2026-117
Project: Slick CarouselDate: 2026-August-26Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: <2.1.0CVE IDs: CVE-2026-81160Description: Slick UI, a sub-module of Slick, enables you to add Slick option sets that may contain HTML for carousel buttons.
Previous releases of the module did not sufficiently validate user input, leading to a Cross Site Scripting (XSS) vulnerability.
Note: This vulnerability was fixed in 8.x-2.1 but that was not marked as a security release at the time.Solution:
- Only the 3.0.x branch is supported by the maintainers. Upgrade to a release on that branch.
Reported By:
- Drew Webber (mcdruid) of the Drupal Security Team
Fixed By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- cilefen of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team

