Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
View online: https://www.drupal.org/sa-contrib-2026-158 Project: Webform [1] Project machine name: webform Date: 2026-September-23 Security risk: *Moderately critical* 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2] Vulnerability: Cross-site scripting Affected versions: <6.2.12 || >=6.3.0 <6.3.1 CVE IDs: CVE-2026-96358 Description: The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. The module includes a rating element, which did not sufficiently validate its data. Under specific circumstances, this could allow cross-site scripting on a page with a rating element. This vulnerability is mitigated by the fact that an attacker must be able to place crafted HTML markup on the same page as a Webform rating element. Solution: Install the latest version: * If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3]. * If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4]. Reported By: * Pierre Rudloff (prudloff) [5] of the Drupal Security Team Fixed By: * Jacob Rockowitz (jrockowitz) [6] * Lee Rowlands (larowlan) [7] of the Drupal Security Team * Pierre Rudloff (prudloff) [8] of the Drupal Security Team Coordinated By: * Swan Kalata (akalata) [9] of the Drupal Security Team * Bram Driesen (bramdriesen) [10] of the Drupal Security Team * Neil Drumm (drumm) [11] of the Drupal Security Team * Jess (xjm) [12] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [13] [1] https://www.drupal.org/project/webform [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/webform/releases/6.2.12 [4] https://www.drupal.org/project/webform/releases/6.3.1 [5] https://www.drupal.org/u/prudloff [6] https://www.drupal.org/u/jrockowitz [7] https://www.drupal.org/u/larowlan [8] https://www.drupal.org/u/prudloff [9] https://www.drupal.org/u/akalata [10] https://www.drupal.org/u/bramdriesen [11] https://www.drupal.org/u/drumm [12] https://www.drupal.org/u/xjm [13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org