Executive brief
The Webform module for Drupal allows site builders to create and manage forms with submission data. The module has a cross-site scripting vulnerability in its JavaScript announcement feature for form updates, which could be exploited by attackers with form administration access to inject malicious code that executes in users' browsers when they interact with affected forms.
Technical details
The vulnerability exists in the JavaScript behaviour that announces dynamic form updates to assistive technologies, caused by improper sanitisation of announcement text. This requires site builder or administrative access to configure malicious announcement text. Affected versions are before 6.2.12 and 6.3.0 before 6.3.1, with patches available in both branches.
Affected products
- Drupal Webform <6.2.12 || >=6.3.0 <6.3.1
Timeline
- 2026-09-23: disclosed