Drupal Webform Module Contains Moderately Critical XSS Vulnerability
A cross-site scripting vulnerability has been identified in the Drupal Webform module. The Drupal Security Team published an advisory on September 23, 2026, assigning it a moderately critical risk rating. The flaw allows unauthorized script execution through the module's custom attributes editor. Affected versions are below 6.2.12 on the 6.2.x branch and versions from 6.3.0 to below 6.3.1. Site administrators are urged to patch immediately or restrict access to the webform editing functionality.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in