Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
View online: https://www.drupal.org/sa-contrib-2026-161 Project: Webform [1] Project machine name: webform Date: 2026-September-23 Security risk: *Moderately critical* 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Cross-site scripting Affected versions: <6.2.12 || >=6.3.0 <6.3.1 CVE IDs: CVE-2026-96363 Description: The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings. This vulnerability is mitigated by the fact that an attacker must have a role with /create webform/ and /edit own webform/ permissions, and the Webform Entity Print module must be enabled. Solution: Install the latest version: * If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3]. * If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4]. Reported By: * Pierre Rudloff (prudloff) [5] of the Drupal Security Team Fixed By: * Dan Chadwick (danchadwick) [6] * Jacob Rockowitz (jrockowitz) [7] * Liam Morland (liam morland) [8] Coordinated By: * Swan Kalata (akalata) [9] of the Drupal Security Team * Bram Driesen (bramdriesen) [10] of the Drupal Security Team * cilefen (cilefen) [11] of the Drupal Security Team * Greg Knaddison (greggles) [12] of the Drupal Security Team * Ivo Van Geertruyen (mr.baileys) [13] of the Drupal Security Team * Juraj Nemec (poker10) [14] of the Drupal Security Team * Jess (xjm) [15] of the Drupal Security Team * Cathy Theys (yesct) [16] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [17] [1] https://www.drupal.org/project/webform [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/webform/releases/6.2.12 [4] https://www.drupal.org/project/webform/releases/6.3.1 [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/danchadwick [7] https://www.drupal.org/u/jrockowitz [8] https://www.drupal.org/u/liam-morland [9] https://www.drupal.org/u/akalata [10] https://www.drupal.org/u/bramdriesen [11] https://www.drupal.org/u/cilefen [12] https://www.drupal.org/u/greggles [13] https://www.drupal.org/u/mrbaileys [14] https://www.drupal.org/u/poker10 [15] https://www.drupal.org/u/xjm [16] https://www.drupal.org/u/yesct [17] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org