Junglewise Threat Intelligence

CVE-2026-96363: Drupal Webform Entity Print cross-site scripting in print templates

CVE-2026-96363 · Severity: info · Published 2026-09-23

Technologies: Drupal Webform, Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform. Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Webform module for Drupal allows site administrators to create and manage forms and collect submission data. The optional Webform Entity Print submodule contains an insufficient access control vulnerability that allows authenticated users with form creation permissions to inject malicious scripts into print template settings. This could allow attackers to execute arbitrary code in the browser of users who view the affected forms, potentially stealing credentials or data.

Technical details

The Webform Entity Print submodule fails to properly validate and restrict access to print templates, allowing users with "create webform" and "edit own webform" permissions to inject XSS payloads into submodule configuration. The vulnerability requires authentication, specific role permissions, and the submodule to be enabled. Patches are available in Webform 6.2.12 and 6.3.1.

Affected products

  • Drupal Webform <6.2.12 or >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed

References

Related threats