Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
This release of 7.x-4.x fixes two security issues, a number of bugs, and introduces new features. Immediate updating is strongly recommended for all users of the 7.x-4.x branch. See SA-CONTRIB-2015-063 - Webform - Cross Site Scripting (XSS) for details.
When a webform is made available as a block, the node's title is used as the default block title. This title is not sufficiently sanitized, leading to a Cross Site Scripting (XSS) vulnerability.
When a webform is made available as a block, the node's title is used as the default block title. This title is not sufficiently sanitized, leading to a Cross Site Scripting (XSS) vulnerability.