Webform
20 security fixes in one update. Webform fixed 20 separate security bugs this week: 10 cross site scripting, 8 access bypass, 1 remote code execution, 1 denial of service. One update covers all of them. The most serious, SA-CONTRIB-2026-175, is explained here and the full list is at the end of the card.
Anyone without logging in could submit data that runs as code when the form is viewed. They could read the entire database and change the underlying website code. They could not do this on forms that do not use special formatting tags.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a form is set up with a custom multiple value format that includes submission value tags.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Webform to 6.2.12 or 6.3.1, whichever branch you are on.
For developers: what the fix changed
Adds the missing `#` prefix to `#format_items_html` and `#format_items_text` in `WebformElementBase.php` to properly exclude multiple-value item formats from token replacement.
Also in this release The release also includes numerous other security fixes, such as XSS mitigations in JavaScript, SSRF protections for remote CSV imports, path traversal prevention in exports, and stricter access controls for remote post handlers and file downloads.
.gitlab-ci.yml+1 −1composer.json+1 −0includes/webform.query.inc+8 −0js/webform.announce.js+1 −1js/webform.dialog.js+1 −1js/webform.element.ajax.js+18 −7js/webform.element.color.js+6 −2js/webform.element.counter.js+18 −0js/webform.element.help.js+1 −1js/webform.element.rating.js+53 −2js/webform.tooltip.js+2 −2js/webform.xss.js+133 −0
- Critical · Remote Code Execution · SA-CONTRIB-2026-175
- Moderately critical · Access bypass · SA-CONTRIB-2026-174
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-172
- Moderately critical · Access bypass · SA-CONTRIB-2026-171
- Moderately critical · Access bypass · SA-CONTRIB-2026-169
- Moderately critical · Access bypass · SA-CONTRIB-2026-168
- Moderately critical · Access bypass · SA-CONTRIB-2026-167
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-166
- Moderately critical · Access bypass, Server side request forgery · SA-CONTRIB-2026-164
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-163
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-162
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-161
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-160
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-159
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-158
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-155
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-154
- Less critical · Access bypass · SA-CONTRIB-2026-173
- Less critical · Denial of service · SA-CONTRIB-2026-170
- Less critical · Access bypass · SA-CONTRIB-2026-165