πŸ” CVE Alert

CVE-2025-12848

UNKNOWN 0.0

XSS vulnerability when rendering filename in Webform Multiform

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
21th

Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name renderer. An unauthenticated attacker can exploit this vulnerability by uploading a file with a malicious filename containing JavaScript code (e.g., "<img src=1 onerror=alert(document.domain)>") to a Webform node with a Multifile field where file type validation is disabled. This allows the execution of arbitrary scripts in the context of the victim's browser. The issue is present in a third-party library and has been addressed in a patch available atΒ  https://github.com/fyneworks/multifile/pull/44 . Users are advised to apply the provided patch or update to a fixed version of the module.

CWE CWE-79
Vendor drupal
Product drupal
Ecosystems
Industries
WebMedia
Published Nov 26, 2025
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for drupal drupal

Be the first to know when new unknown vulnerabilities affecting drupal drupal are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Drupal / Drupal
7.x-1.0 ≀ 7.x-1.6

References

NVD β†— CVE.org β†— EPSS Data β†—
drupal.org: https://www.drupal.org/node/3105204 d7security.org: https://www.d7security.org/security-advisories/D7SECURITY-SA-CONTRIB-2025-001/ herodevs.com: https://www.herodevs.com/vulnerability-directory/cve-2025-12848 d7es.tag1.com: https://d7es.tag1.com/security-advisories/webform-multiple-file-upload-critical-cross-site-scripting