chiprook
← Security
SecuritySeptember 28, 2026, 06:20

CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core

Drupal advisory SA-CONTRIB-2026-161, published September 23, 2026, covers CVE-2026-96363 in the Webform Entity Print submodule, not Drupal core. The XSS requires both the enabled submodule and the create webform and edit own webform permissions. Fixed in Webform 6.2.12 and 6.3.1.

CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core
#Drupal#Webform
Read next
Security

CERT-BUND flags 36 CVEs in 16 Drupal projects, CVSS 9.8

Business

Tesla registers local entity in Vietnam to target Southeast Asia's largest EV market

Software

Google Maps leak reveals 72 ranking signals and Geostore entity model

Security

Fake Google Security Team ad bans script reading — then prints the script