{"id":"DRUPAL-CONTRIB-2021-026","details":"The Webform module uses the [CKEditor](https://github.com/ckeditor/ckeditor4), library for WYSIWYG editing. CKEditor has released [a security update that impacts Webform](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/).\n\nAn attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit one or more Cross-Site Scripting (XSS) vulnerabilities to target users with access to the WYSIWYG CKEditor, including site admins with privileged access.\n\nFor more information, see [CKEditor's announcement of the release](https://ckeditor.com/blog/ckeditor-4.16.2-with-browser-improvements-and-security-fixes/).","modified":"2026-09-10T03:46:17.357572537Z","published":"2021-08-25T15:27:54Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2021-026"}],"affected":[{"package":{"name":"drupal/webform","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/webform?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.28.0"}],"database_specific":{"constraint":"\u003c5.28.0"}},{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.5"}],"database_specific":{"constraint":"\u003e=6.0.0 \u003c6.0.5"}}],"database_specific":{"affected_versions":"\u003c5.28.0 || \u003e=6.0.0 \u003c6.0.5","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/webform/DRUPAL-CONTRIB-2021-026.json"}}],"schema_version":"1.9.0","credits":[{"name":"Lee Rowlands","contact":["https://www.drupal.org/user/395439"]}]}