Junglewise Threat Intelligence

CVE-2026-96367: Drupal Webform module cross-site scripting in YAML editor

CVE-2026-96367 · Severity: info · Published 2026-09-23

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform, Drupal Webform. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Webform module for Drupal allows site administrators to build forms and collect submissions. A flaw in the custom attributes YAML editor fails to properly restrict access, allowing users with form-editing permissions to inject malicious code that executes in other users' browsers, potentially compromising sensitive form data or redirecting site visitors.

Technical details

The Webform module does not sufficiently restrict access to the custom attributes YAML editor, allowing users with webform create or edit permissions (but without source edit permissions) to add custom attributes that lead to stored cross-site scripting. An authenticated attacker with the webform editor role can inject arbitrary JavaScript into form definitions, which executes when other users view or interact with the affected forms. Patches are available in versions 6.2.12 and 6.3.1 and later.

Affected products

  • Drupal Webform <6.2.12 or >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Fixed in versions 6.2.12 and 6.3.1

References

Related threats