Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite ›

Newsfeed-Generator

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171

Drupal Contrib Security - 23 September, 2026 - 18:26
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 14 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Exploit/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96364Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The Webform Share submodule can expose a webform for embedding on another site.

Under certain circumstances, submissions for an Ajax-enabled Webform using Webform Share can bypass anti-spam protections.

This vulnerability is mitigated by the fact that Webform Share must be enabled, sharing must be enabled for the affected webform, and the affected webform must rely on compatible Form-API-based anti-spam protections such as Honeypot or Antibot.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • karing
Fixed By: 
  • Alan Dixon (adixon)
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Mori Sugimoto (dokumori) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Less critical - Denial of service - SA-CONTRIB-2026-170

Drupal Contrib Security - 23 September, 2026 - 18:26
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Less critical 8 ∕ 25 AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:UncommonVulnerability: Denial of serviceAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96365Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Forms may be displayed in blocks.

Webform does not sufficiently validate an optional token query value before using it. Under specific configurations where a Webform is rendered for anonymous visitors, a malicious request can cause the request to consume significant resources leading to a Denial of Service.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Majdi Alomari (majdi)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169

Drupal Contrib Security - 23 September, 2026 - 18:25
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:None/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96366Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Site builders may also configure handlers for processing submissions, including email handlers that may include uploaded files as attachments.

In affected configurations, Webform did not sufficiently validate a managed file upload element when processing a new submission. A user with access to submit a vulnerable webform could potentially access other managed files they were not authorized to view.

This vulnerability is mitigated by the fact that a site must have a Webform with a managed file upload element and a configuration that exposes submitted files, such as allowing users to view their own webform submissions or sending uploads as email attachments.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Sandro Kneubühl (blackpharao)
  • omidsec
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Heine Deelstra (heine) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Mohit Aghera (mohit_aghera) provisional member of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168

Drupal Contrib Security - 23 September, 2026 - 18:20
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96373Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently validate requested filenames when serving generated submission exports. Under certain configurations, a user with permission to view submission results for one webform may be able to access or remove files from the configured export temporary directory that were not generated for that webform.

This vulnerability is mitigated by the fact that an attacker must have access to view submission results for a webform and must know or be able to determine a target filename.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167

Drupal Contrib Security - 23 September, 2026 - 18:18
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96372Description: 

The Webform module enables site builders to create forms and collect submissions.

The module does not sufficiently restrict access to configure Remote HTTP Operations handlers. This vulnerability could allow a user with permission to edit a webform to configure a remote HTTP operation.

The update adds the Administer webform remote post URLs permission. Review this permission and ensure it is granted only to trusted roles.

The vulnerability is mitigated by the fact that an attacker must have a role with permission to edit a webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.11.

Review the new permission Administer webform remote post URLs and ensure it is only granted to trusted roles.

Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Wesley Giles (seraphdev)
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166

Drupal Contrib Security - 23 September, 2026 - 18:17
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96371Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently restrict access to raw webform source editing when the Webform UI module is not enabled. This could allow a user with webform creation or editing permissions to enter source configuration that is rendered unsafely.

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit webforms.

Solution: 

Install the latest version.

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Liam Morland (liam morland)
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Less critical - Access bypass - SA-CONTRIB-2026-165

Drupal Contrib Security - 23 September, 2026 - 18:17
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Less critical 8 ∕ 25 AC:Complex/A:User/CI:Some/II:None/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96369Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

When Webform is used with JSON:API enabled, submissions may be cached without varying correctly by the authenticated user. If a webform is configured so that authenticated users can view their own submissions, a request to the JSON:API webform submission collection can return a cached response generated for a different user.

This can allow an authenticated user to view another user's webform submission data through the JSON:API collection endpoint.

This vulnerability is mitigated by the fact that JSON:API must be enabled, the affected webform must expose submissions through JSON:API, and the attacker must have an account with permission to view their own submissions for the affected webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Giuseppe (giuseppe87)
Fixed By: 
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Jacob Rockowitz (jrockowitz)
  • Juraj Nemec (poker10) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164

Drupal Contrib Security - 23 September, 2026 - 18:16
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Access bypass, Server-side request forgeryAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96370Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module includes a Webform Submission Export/Import submodule that allows importing submission data from uploaded CSV files or remote URLs.

The submodule did not sufficiently validate access to export/import functionality. A user who could edit webform submissions and access webform results could also access the import interface, including the remote URL import path, leading to a server-side request forgery vulnerability.

Sites that do not enable the Webform Submission Export/Import submodule are not affected.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.

For sites that need remote imports, explicitly configure the trusted hosts in settings.php:

$settings['webform_submission_export_import_csv_hosts'] = ['staging.example.com']; $settings['webform_submission_export_import_file_hosts'] = ['files.staging.example.com', '*.google.com']; Reported By: 
  • abdo.boutanos@richemont.com
  • chulhan park (cjfgks1230)
  • Abdulhakeem Onipede (kism37)
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Marcus Johansson (marcus_johansson)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Drew Webber (mcdruid) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163

Drupal Contrib Security - 23 September, 2026 - 18:16
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96368Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may add tooltips and help text to these forms.

Some Webform tooltips and help text were not sufficiently sanitized, resulting in possible cross-site scripting (XSS).

This vulnerability is mitigated by the fact that an attacker must have permission to create or edit affected Webform configuration or content.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162

Drupal Contrib Security - 23 September, 2026 - 18:15
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Proof/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96367Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently restrict access to the custom attributes YAML editor. Users with permission to create or edit webforms (but without permission to edit webform source) may be able to add custom attributes, leading to cross-site scripting.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit webforms.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Mitch Portier (arkener)
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161

Drupal Contrib Security - 23 September, 2026 - 18:14
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 10 ∕ 25 AC:Complex/A:Admin/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96363Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.

This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Dan Chadwick (danchadwick)
  • Jacob Rockowitz (jrockowitz)
  • Liam Morland (liam morland)
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Cathy Theys (yesct) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160

Drupal Contrib Security - 23 September, 2026 - 18:14
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96362Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Site builders may also configure handlers for processing submissions. Remote Post Handlers send webform data to other servers via APIs.

The module does not sufficiently filter response values from the Remote Post handler before those values are rendered through handler response tokens. If a site uses Remote Post handler response tokens in rendered output, values returned by a configured remote endpoint could be rendered as HTML, resulting in a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to control or influence the response from a configured remote endpoint, and the site must use Remote Post handler response tokens in rendered output.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Brian Willows (hsjbrianwillows)
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • cilefen (cilefen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159

Drupal Contrib Security - 23 September, 2026 - 18:13
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96359Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module did not sufficiently sanitize attributes used by its color element. Under certain conditions, specially crafted attributes could result in cross-site scripting (XSS) when the element is rendered.

This vulnerability is mitigated by the fact that an attacker must be able to add a specially crafted link with a specific class to the same page as the affected webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158

Drupal Contrib Security - 23 September, 2026 - 18:13
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96358Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module includes a rating element, which did not sufficiently validate its data. Under specific circumstances, this could allow cross-site scripting on a page with a rating element.

This vulnerability is mitigated by the fact that an attacker must be able to place crafted HTML markup on the same page as a Webform rating element.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Neil Drumm (drumm) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155

Drupal Contrib Security - 23 September, 2026 - 18:11
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 12 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96361Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module does not sufficiently sanitize text counter configuration before passing options to the bundled jQuery Text Counter library. Under certain configurations, this can allow markup from counter-related settings to be inserted into the page leading to a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to create or edit affected Webform elements, or place specially crafted counter markup on a page where the Webform counter JavaScript is active.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154

Drupal Contrib Security - 23 September, 2026 - 18:11
Project: WebformProject machine name: webformDate: 2026-September-23Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:Admin/CI:Some/II:Some/E:Theoretical/TD:UncommonVulnerability: Cross-site scriptingAffected versions: <6.2.12 || >=6.3.0 <6.3.1CVE IDs: CVE-2026-96360Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

The module provides JavaScript behaviours for announcing dynamic form updates to assistive technologies.

In some configurations, due to improper sanitisation, specially crafted announcement text could create a cross-site scripting risk for users interacting with the affected Webform.

Solution: 

Install the latest version:

  • If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12.
  • If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1.
Reported By: 
  • Pierre Rudloff (prudloff) of the Drupal Security Team
Fixed By: 
  • Jacob Rockowitz (jrockowitz)
  • Lee Rowlands (larowlan) of the Drupal Security Team
Coordinated By: 
  • Swan Kalata (akalata) of the Drupal Security Team
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Upcoming critical contributed project security release on September 23, 2026 - PSA-2026-09-21

Drupal PSA Security - 21 September, 2026 - 11:56
Date: 2026-September-21Description: 
  • Updated 2026-09-22, 12:00 UTC, to document that the advisories in the release might be possible for more common configurations, and that other projects may have advisories.
  • Updated 2026-09-21, 19:00 UTC, to document that this is not covered by Drupal Steward.

There will be a security release for a widely used contributed module on September 23, 2026 between 17:00 and 21:00 UTC.

We are announcing this release in advance because the affected contributed module is used on a significant portion of Drupal sites, and the upcoming release will include a significant number of advisories.

The advisory with the highest risk score for the release is currently rated as critical. Other, less severe advisories in the release may be accessible to anonymous users, or result from default configurations.

Other contributed projects may also release advisories on the same date, possibly with more severe vulnerabilities. Drupal core is not affected.

Drupal Steward information

These releases will not be covered by Drupal Steward.

Advisories may be published in batches (a few at a time)

The current rate of advisories may require changes to our practices going forward:

  • The security team may publish advisories individually, at different times inside the window.
  • We will try to publish batches grouped by module.
  • We will announce in Slack when all planned releases for the day are complete.
  • We will release mailing list emails about the security updates together at the end of the window, to reduce the risk of site owners updating multiple times while advisories are still being published.

These changes are intended to make the process easier for the team and to make communication from the team easier to follow.

No special release procedures

The planned update does not require special release procedures.

Solution: 

Update, 2026-09-23 18:30 UTC: The Webform project has released the below 20 advisories today. Make note of the critical advisory SA-CONTRIB-2026-175, which has slightly increased severity than was originally noted in this public service announcement.

Other advisories than those below were published for other projects, so site owners should follow all normal update procedures.

  1. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
  2. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155
  3. (Advisory numbers 156 and 157 were accidentally skipped in how we applied the numbering; these are not missing security advisories.)
  4. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
  5. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
  6. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
  7. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
  8. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
  9. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
  10. Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
  11. Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
  12. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
  13. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
  14. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
  15. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
  16. Webform - Less critical - Denial of service - SA-CONTRIB-2026-170
  17. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
  18. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
  19. Webform - Less critical - Access bypass - SA-CONTRIB-2026-173
  20. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
  21. Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Moshe Weitzman (moshe weitzman) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Drupal core - Moderately critical - Third-party libraries - SA-CORE-2026-013

Drupal Core Security - 16 September, 2026 - 18:21
Project: Drupal coreProject machine name: drupalDate: 2026-September-16Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Third-party librariesAffected versions: >=10.5.0 <10.6.17 || >=11.0.0 <11.3.17 || >=11.4.0 <11.4.7Description: 

The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal.

Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.

For more information, see CKEditor's security advisory:

  • High-severity Cross-site scripting (XSS) in the engine package
Solution: 

Install the latest version:

Drupal 11

  • If you use Drupal 11.4.x, update to Drupal 11.4.7.
  • If you use Drupal 11.3.x, update to Drupal 11.3.17.
  • Drupal 11.2.x and below are end-of-life and do not receive security coverage.

Drupal 10

  • If you use Drupal 10.6.x, update to Drupal 10.6.17.
  • Drupal 10.5.x and below are end-of-life and do not receive security coverage.

Note that Drupal 8 and Drupal 9 have both reached end-of-life.

Instructions for contributed modules

Site owners should also review their site following the protocol for managing external libraries and plugins, as contributed projects may use additional CKEditor plugins not packaged in Drupal core.

CKEditor has also released another CVE in today's release that does not affect Drupal, but may affect custom plugins or other usecases:

  • Low-severity Cross-site scripting (XSS) in the engine package
Reported By: 
  • Piotrek Koszuliński (Reinmar)
Fixed By: 
  • catch (catch) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Mohit Aghera (mohit_aghera), provisional member of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • catch (catch) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Lee Rowlands (larowlan) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Ultimate Table Field - Critical - Access bypass - SA-CONTRIB-2026-153

Drupal Contrib Security - 9 September, 2026 - 19:24
Project: Ultimate Table FieldProject machine name: ultimate_table_fieldDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <1.1.1 || >=2.0.0 <2.0.1CVE IDs: CVE-2026-87955Description: 

The Ultimate Table Field module enables you to store table data in a field and edit each table cell through a dialog, using cell field plugins such as text, link, and file.

The module doesn't sufficiently protect the route that opens the cell editor dialog. The route is accessible to anonymous users, who can open the dialog for any cell type. The dialog allows uploading files to the server location.

This vulnerability is partially mitigated by the fact that only files with the pdf, doc and docx extensions are accepted.

Solution: 

Install the latest version and adjust permissions:

  • If you use the 2.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 2.0.1.
  • If you use the 1.x branch of the Ultimate Table Field module , upgrade to Ultimate Table Field 1.1.1.

After updating, grant the new permission Use the Ultimate Table Field cell editor to every role that edits content containing an Ultimate Table field. Without it, editors can no longer open the cell editor dialog.

Releases of the 1.0.x branch are not supported and do not receive security coverage. Upgrade to 1.1.1 or 2.0.1.

Reported By: 
  • Marcus Johansson (marcus_johansson)
Fixed By: 
  • Brahim Khouy (b.khouy)
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security

Taxonomy Term Glossary - Critical - Access bypass - SA-CONTRIB-2026-152

Drupal Contrib Security - 9 September, 2026 - 19:24
Project: Taxonomy Term GlossaryProject machine name: term_glossaryDate: 2026-September-09Security risk: Critical 15 ∕ 25 AC:None/A:None/CI:Some/II:None/E:Theoretical/TD:AllVulnerability: Access bypassAffected versions: <4.6.0CVE IDs: CVE-2026-87954Description: 

This module adds automatic highlighting of taxonomy terms in content.

The module doesn't sufficiently check access on taxonomy terms. As a result, anonymous users can view any of the site's taxonomy terms at the module's JSON endpoint, including taxonomy terms that are unpublished or otherwise restricted.

Solution: 

Install the latest version:

  • If you use the Taxonomy Term Glossary module, upgrade to term_glossary 4.6.0.

The 4.4.x and 4.5.x branches are no longer supported.

Reported By: 
  • Hemant Gupta (guptahemant)
  • Marcus Johansson (marcus_johansson)
  • Serhii Checheniev (serhii-che)
Fixed By: 
  • Frank Mably (mably)
Coordinated By: 
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Juraj Nemec (poker10) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
  • Swan Kalata (akalata) of the Drupal Security Team
Kategorien: Drupal Security
  • « erste Seite
  • ‹ vorherige Seite
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • nächste Seite ›
  • letzte Seite »

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 2 Wochen 1 Tag
  • Vielen Dank für Ihren
    vor 2 Wochen 3 Tagen
  • Composer ist sehr ratsam
    vor 2 Wochen 5 Tagen
  • Vielen Dank für den
    vor 3 Wochen 1 Tag
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 1 Tag
  • Gut gemacht
    vor 3 Wochen 1 Tag
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 1 Tag
  • Links
    vor 3 Wochen 4 Tagen
  • Moin,wow, sehr gutes
    vor 3 Wochen 5 Tagen
  • Dass ist eine spannende
    vor 3 Wochen 5 Tagen

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 46 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association