CVE-2025-12761: Simple multi step form - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-116
Published Nov 18, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Site Scripting (XSS).This issue affects Simple multi step form: from 0.0.0 before 2.0.0.
Affected Software
3 affected componentsFixes available
Drupal Simple multi step form<2.0.0
composer/drupal/simple_multistep<2.0.0
2.0.0
Simple Multi Step Form Project Simple Multi Step Form Drupal<2.0.0
Remediation
Patch Available
Event History
Nov 18, 2025
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyAffected Software
Advisory Published
via GitHub·06:32 PM
Data Sourced
via GitHub·06:32 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12761?
CVE-2025-12761 is classified as a high-severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-12761?
To resolve CVE-2025-12761, update the Simple multi step form module to version 2.0.0 or later.
3
What software is affected by CVE-2025-12761?
CVE-2025-12761 affects the Drupal Simple multi step form versions before 2.0.0.
4
What type of vulnerability is CVE-2025-12761?
CVE-2025-12761 involves improper neutralization of input leading to Cross-Site Scripting (XSS).
5
Can CVE-2025-12761 be exploited by an attacker?
Yes, an attacker can exploit CVE-2025-12761 to execute malicious scripts in the context of a user's browser.