Junglewise Threat Intelligence

CVE-2026-96359: Drupal Webform color element cross-site scripting

CVE-2026-96359 · Severity: info · Published 2026-09-23

Technologies: Drupal Webform, Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform. Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Webform module for Drupal allows site administrators to build online forms and manage submissions. An insufficient sanitization flaw in the color element could allow an attacker who has placed a specially crafted link on the same page to inject malicious scripts, potentially compromising visitors' sessions or stealing sensitive form data.

Technical details

The vulnerability is a DOM-based or reflected XSS in the color element's attribute rendering due to inadequate sanitization. An attacker must be able to place a specially crafted link with a specific class on the same page as the webform to trigger the vulnerability. The issue affects versions before 6.2.12 and 6.3.0 through 6.3.0, with fixes available in 6.2.12 and 6.3.1.

Affected products

  • Drupal Webform <6.2.12 or >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: 6.2.12 and 6.3.1 releases

References

Related threats