The Flag Module Project maintains a narrowly scoped web-application module where vulnerabilities center on server-side code generation and client-side rendering, reflecting the attack surface inherent to dynamic template and scripting environments. Observed weakness classes include code injection and cross-site scripting, which recur as inputs flow through the module's generation and output pathways. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flag Module Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14556MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Flag allows Cross-Site Scripting (XSS).This issue affects Flag: | Jan 14, 2026 | 5.4 | 20 | NO | NO |
CVE-2014-3453MEDIUM Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authent | May 17, 2014 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flag Module Project.
Media articles that mention a CVE ID that affects a product developed by Flag Module Project — matched by CVE ID, not by vendor name.