Urgent Drupal Security Alert: Massive Webform Vulnerability Threatens Thousands of Websites – Update Immediately!

Urgent Drupal Security Alert: Massive Webform Vulnerability Threatens Thousands of Websites – Update Immediately!
Authored on

A major security release has hit the Drupal community! The maintainers of the widely-used Drupal Webform module have rolled out critical emergency updates—releases 6.3.1 (for Drupal 9, 10, 11) and 6.2.12 (for Drupal 9, 10, 11)—fixing 22 coordinated vulnerabilities.

Among the patches is a critical Remote Code Execution (RCE) flaw alongside multiple Cross-Site Scripting (XSS), Access Bypass, and Server-Side Request Forgery (SSRF) vulnerabilities. These exploits put site submission data, file uploads, and server security at immediate risk.

Site builders are urged to update via Composer right away to patch these holes and protect their platforms from potential attacks. Don't wait until it's too late—securing your Webform module today is vital!

Source: Release 6.2.12
Source: Release 6.3.1