CVE-2026-96363
Description
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data. Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings. This vulnerability is mitigated by the fact that an attacker must have a role with *create webform* and *edit own webform* permissions, and the Webform Entity Print module must be enabled.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist:https://packages.drupal.org/8 | drupal/webform | <6.2.12||>=6.3.0,<6.3.1 | 6.2.12 |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.