chiprook
← Security
SecurityOctober 10, 2026, 03:00

Drupal Webform XSS CVE-2026-96367 hits custom attributes editor

A cross-site scripting flaw, CVE-2026-96367, was found in the Drupal Webform module: the custom attributes YAML editor lacks sufficient access control, letting a user with permission to create or edit webforms inject scripts. Versions below 6.2.12 and 6.3.0–6.3.1 are affected; fixes are 6.2.12 and 6.3.1.

Drupal Webform XSS CVE-2026-96367 hits custom attributes editor
#Drupal#Webform
Read next
Security

CVE-2026-96364 in Drupal: 16 modules affected, detection only by version

Security

CVE-2026-96366 in Drupal Webform: managed file access bypass

Security

CVE-2026-96363 Is a Webform Entity Print Submodule Issue, Not Drupal Core

Security

CERT-BUND flags 36 Drupal module flaws, including Webform and REST API