SA-CONTRIB-2026-163: XSS
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may add tooltips and help text to these forms. Some Webform tooltips and help text were not sufficiently sanitized, resulting in possible cross-site scripting (XSS). This vulnerability is mitigated by the fact that an attacker must have permission to create or edit affected Webform configuration or content.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/webformto a version that resolves this vulnerability.Fixed in 6.2.12Fixed in 6.3.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must have permission to create or edit affected Webform configuration or content. This limits exploitation to users with those permissions.
Which Webform features are implicated?
The issue affects some tooltips and help text configured in Webform forms. These fields were not sufficiently sanitized and may allow cross-site scripting.