CVE-2009-4532
Drupal Webform <5.2.8-6.2.8 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creation privileges, to inject arbitrary web script or HTML via a field label.
References (6)
Scores
EPSS
0.0026
EPSS Percentile
49.3%
Classification
CWE
CWE-79
Status
published
Affected Products (43)
nathan_haug/webform
< 5.x-2.7
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
nathan_haug/webform
... and 28 more
Timeline
Published
Dec 31, 2009
Tracked Since
Feb 18, 2026