Junglewise Threat Intelligence

CVE-2026-96368: Drupal Webform cross-site scripting in tooltips and help text

CVE-2026-96368 · Severity: info · Published 2026-09-23

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform, Drupal Webform. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Webform module for Drupal allows site builders to create online forms and collect submissions. Insufficient sanitization of tooltips and help text can allow malicious code injection, potentially compromising users who interact with these forms. Exploitation requires the attacker to have permissions to create or edit Webform configuration, limiting risk to insider threats or compromised administrative accounts.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Webform module due to inadequate sanitization of tooltip and help text fields. The vulnerability requires an authenticated attacker with form creation or editing permissions (Access Control: Basic). Exploitation results in arbitrary JavaScript execution in the context of users viewing the affected forms.

Affected products

  • Drupal Webform <6.2.12 and >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Versions 6.2.12 and 6.3.1 available

References

Related threats