Drupal Webform XSS CVE-2026-96367 hits custom attributes editor
A cross-site scripting flaw, CVE-2026-96367, was found in the Drupal Webform module: the custom attributes YAML editor lacks sufficient access control, letting a user with permission to create or edit webforms inject scripts. Versions below 6.2.12 and 6.3.0–6.3.1 are affected; fixes are 6.2.12 and 6.3.1.
- CVE-2026-96367 is rated moderately critical at 13/25
- Exploit requires a role allowed to create or edit webforms
- Affected: Webform below 6.2.12 and 6.3.0–6.3.1
- ZoomEye returned 436,325 instances matching the Drupal fingerprint
Read next
Security