Navbar - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2022-005
This module provides a very simple, mobile-friendly navigation toolbar.
The module doesn't sufficiently check for user-provided input.
This vulnerability is mitigated by the fact that an attacker must have the ability to post content using a text format (like the default "Filtered HTML" format) that won't filter out the exploit code.
- Navbar versions prior to 1.x-1.8.0