DRUPAL-CONTRIB-2021-026

    Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2021-026

    DRUPAL-CONTRIB-2021-026

    Published: 25 Aug 2021Last Modified: 10 Sept 2026

    Summary:

    Details: The Webform module uses the [CKEditor](https://github.com/ckeditor/ckeditor4), library for WYSIWYG editing. CKEditor has released [a security update that impacts Webform](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/). An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access. For more information, see [CKEditor's announcement of the release](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/).

    Affected packages

    Package

    Name: drupal/webform

    Purl: pkg:composer/drupal/webform?repository_url=https:%2F%2Fpackages.drupal.org%2F8

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.28.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DRUPAL-CONTRIB-2021-026 | CVE-DB