Project: 
Project machine name: 
webform
Date: 
2026-September-23
Vulnerability: 
Cross-site scripting
Affected versions: 
<6.2.12 || >=6.3.0 <6.3.1
CVE IDs: 
CVE-2026-96363
Description: 

The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.

Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.

This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: