Executive brief
The Webform module for Drupal allows site builders to create and manage web forms with user submissions. A flaw in the rating element component fails to properly validate data, potentially allowing an attacker to inject malicious scripts that execute in users' browsers. The attack requires the attacker to have the ability to place crafted HTML on the same page as the vulnerable rating element, which significantly limits the real-world impact.
Technical details
The Webform rating element does not sufficiently validate input data, enabling reflected cross-site scripting (XSS) under specific circumstances. The vulnerability affects versions before 6.2.12 and versions 6.3.0 through 6.3.0 (fixed in 6.3.1). Exploitation requires an attacker with the ability to place malicious HTML markup on a page containing a Webform rating element, making this a low-privilege attack vector with limited practical exploitability.
Affected products
- Drupal Webform before 6.2.12, 6.3.0 to before 6.3.1
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched