Webform Project maintains a form-building module that, despite narrow scope, achieves prominence through its embedding in the Drupal ecosystem and deployment across numerous websites. The observed vulnerability signal centers on cross-site scripting issues arising from improper input neutralization in rendered form output, a pattern characteristic of web-form handling components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webform Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.23, 7.x-3.x before 7.x-3.23, and 7.x-4.x before 7.x-4.5 for Drupal allows remote authenticated users wit | Jun 16, 2015 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Webform module before 6.x-3.22, 7.x-3.x before 7.x-3.22, and 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users wit | Jun 15, 2015 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the view-based webform results table in the Webform module 7.x-4.x before 7.x-4.4 for Drupal allows remote authenticated users with cert | Jun 15, 2015 | 3.5 | 13 | NO | NO |
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.20, 7.x-3.x before 7.x-3.20, and 7.x-4.x before 7.x-4.0-beta2 for Drupal allows remote authentic | Oct 17, 2014 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webform Project.
Media articles that mention a CVE ID that affects a product developed by Webform Project — matched by CVE ID, not by vendor name.