—
DRUPAL-CONTRIB-2026-158
Details
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The module includes a rating element, which did not sufficiently validate its data. Under specific circumstances, this could allow cross-site scripting on a page with a rating element.
This vulnerability is mitigated by the fact that an attacker must be able to place crafted HTML markup on the same page as a Webform rating element.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/webform
Introduced in:
0Fixed in: 6.2.12Upgrade drupal/webform to 6.2.12 or newer (ecosystem packagist:https://packages.drupal.org/8).