VDB
Sign up

DRUPAL-CONTRIB-2026-161

Details

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.

This vulnerability is mitigated by the fact that an attacker must have a role with *create webform* and *edit own webform* permissions, and the Webform Entity Print module must be enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/webform
Introduced in: 0Fixed in: 6.2.12

Upgrade drupal/webform to 6.2.12 or newer (ecosystem packagist:https://packages.drupal.org/8).

References