Junglewise Threat Intelligence

CVE-2026-96371: Drupal Webform module cross-site scripting in source editing

CVE-2026-96371 · Severity: info · Published 2026-09-23

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform, Drupal Webform. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

The Webform module for Drupal allows site builders to create and manage forms on websites. When the Webform UI module is disabled, the module fails to properly restrict access to raw webform source editing, allowing users with form creation permissions to inject malicious code that gets rendered unsafely. This could enable attackers with webform editing privileges to execute arbitrary scripts in the context of the site, potentially compromising user data or session cookies.

Technical details

This is a cross-site scripting (XSS) vulnerability in the Webform module's source configuration handling. When the Webform UI module is not enabled, insufficient access controls on raw webform source editing allow authenticated users with webform creation or editing permissions to enter unsanitized configuration that is rendered without proper escaping. An attacker requires webform creation or editing permissions on the Drupal site to exploit this vulnerability; affected versions are 6.2.x prior to 6.2.12 and 6.3.0 prior to 6.3.1.

Affected products

  • Drupal Webform <6.2.12, >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed

References

Related threats