CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core
Drupal advisory SA-CONTRIB-2026-161, published September 23, 2026, covers CVE-2026-96363 in the Webform Entity Print submodule, not Drupal core. The XSS requires both the enabled submodule and the create webform and edit own webform permissions. Fixed in Webform 6.2.12 and 6.3.1.
- CVE-2026-96363 affects the Webform Entity Print submodule, not Drupal core
- XSS requires the enabled submodule plus create webform and edit own webform permissions
- Fixes: Webform 6.2.12 on 6.2.x and 6.3.1 on 6.3.x
- ZoomEye: 436,397 Drupal assets, but 0 matches for CVE-2026-96363
Read next
Security