Drupal security updates, in plain English · Module

Webform

342,248 sites report using it · on drupal.org · 1 security update explained here

This module allows you to build forms to collect data and send it to other systems.

Below is every security update for Webform that this site has covered, newest first. Each one says who could exploit it, whether it applies to your site, how urgent it is, and what to tell your developer. If your site uses this module and you are not sure which version, that is the first question to ask whoever looks after it.

Webform

Critical · 342,248 sites report using it · 20 security fixes · Week of 23 September 2026

20 security fixes in one update. Webform fixed 20 separate security bugs this week: 10 cross site scripting, 8 access bypass, 1 remote code execution, 1 denial of service. One update covers all of them. The most serious, SA-CONTRIB-2026-175, is explained here and the full list is at the end of the card.

Anyone without logging in could submit data that runs as code when the form is viewed. They could read the entire database and change the underlying website code. They could not do this on forms that do not use special formatting tags.

  • Who could do thisAnyone visiting the site. No login needed.
  • Does it apply to youThis applies if a form is set up with a custom multiple value format that includes submission value tags.
  • Has it been used in attacksNo sign of it.
  • How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.

Tell your developerUpdate Webform to 6.2.12 or 6.3.1, whichever branch you are on.

For developers: what the fix changed

This release carries 20 security fixes. The summary below is for SA-CONTRIB-2026-175, the most serious of them.

Adds the missing `#` prefix to `#format_items_html` and `#format_items_text` in `WebformElementBase.php` to properly exclude multiple-value item formats from token replacement.

Also in this release The release also includes numerous other security fixes, such as XSS mitigations in JavaScript, SSRF protections for remote CSV imports, path traversal prevention in exports, and stricter access controls for remote post handlers and file downloads.

6.2.11 to 6.2.12 27 commits, 75 files including 33 tests.

  • .gitlab-ci.yml +1 −1
  • composer.json +1 −0
  • includes/webform.query.inc +8 −0
  • js/webform.announce.js +1 −1
  • js/webform.dialog.js +1 −1
  • js/webform.element.ajax.js +18 −7
  • js/webform.element.color.js +6 −2
  • js/webform.element.counter.js +18 −0
  • js/webform.element.help.js +1 −1
  • js/webform.element.rating.js +53 −2
  • js/webform.tooltip.js +2 −2
  • js/webform.xss.js +133 −0

Full diff, 6.2.11 to 6.2.12 · Full diff, 6.3.0 to 6.3.1

The comparison is against the release immediately before the fix. If your site is on an older release, more will have changed.

All 20 security bugs this update fixes, worst first. Each link is the drupal.org notice for that one.

Not sure what your site is running?

Send me your Drupal site's address.

I'll tell you what I can see from outside, what the Drupal 10 end of life on 9 December means for it, and what it would cost to have me keep it patched. There's no charge for that and no obligation. peter@peterbrady.co.uk


Get in touch

Tell me who you are, what your organisation does, and what you need. That might be a Drupal site that needs looking after, an upgrade to get done before December, or an agency that needs Drupal cover.

If I can help, I'll say so and suggest a call. If I can't, I'll tell you straight away rather than waste your time.

peter@peterbrady.co.uk

For context: I work mainly with UK charities, membership bodies and research organisations, and with the agencies that look after their websites. Not recruiters.

Or start smaller and connect with me on LinkedIn. That's where I post what I find digging around in charity and grants data, and where the free tools turn up first.