—
DRUPAL-CONTRIB-2026-171
Details
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
The Webform Share submodule can expose a webform for embedding on another site.
Under certain circumstances, submissions for an Ajax-enabled Webform using Webform Share can bypass anti-spam protections.
This vulnerability is mitigated by the fact that Webform Share must be enabled, sharing must be enabled for the affected webform, and the affected webform must rely on compatible Form-API-based anti-spam protections such as Honeypot or Antibot.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/webform
Introduced in:
0Fixed in: 6.2.12Upgrade drupal/webform to 6.2.12 or newer (ecosystem packagist:https://packages.drupal.org/8).