Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
View online: https://www.drupal.org/sa-contrib-2026-154 Project: Webform [1] Project machine name: webform Date: 2026-September-23 Security risk: *Moderately critical* 11 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2] Vulnerability: Cross-site scripting Affected versions: <6.2.12 || >=6.3.0 <6.3.1 CVE IDs: CVE-2026-96360 Description: The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. The module provides JavaScript behaviours for announcing dynamic form updates to assistive technologies. In some configurations, due to improper sanitisation, specially crafted announcement text could create a cross-site scripting risk for users interacting with the affected Webform. Solution: Install the latest version: * If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3]. * If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4]. Reported By: * Pierre Rudloff (prudloff) [5] of the Drupal Security Team Fixed By: * Jacob Rockowitz (jrockowitz) [6] * Lee Rowlands (larowlan) [7] of the Drupal Security Team Coordinated By: * Swan Kalata (akalata) [8] of the Drupal Security Team * Bram Driesen (bramdriesen) [9] of the Drupal Security Team * Pierre Rudloff (prudloff) [10] of the Drupal Security Team * Jess (xjm) [11] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [12] [1] https://www.drupal.org/project/webform [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/webform/releases/6.2.12 [4] https://www.drupal.org/project/webform/releases/6.3.1 [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/jrockowitz [7] https://www.drupal.org/u/larowlan [8] https://www.drupal.org/u/akalata [9] https://www.drupal.org/u/bramdriesen [10] https://www.drupal.org/u/prudloff [11] https://www.drupal.org/u/xjm [12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org