—
DRUPAL-CONTRIB-2026-161
Details
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.
This vulnerability is mitigated by the fact that an attacker must have a role with *create webform* and *edit own webform* permissions, and the Webform Entity Print module must be enabled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/webform
Introduced in:
0Fixed in: 6.2.12Upgrade drupal/webform to 6.2.12 or newer (ecosystem packagist:https://packages.drupal.org/8).