Cross-Site Scripting Vulnerability in Webform Multiple File Upload Module for Drupal
CVE-2025-12848
What is CVE-2025-12848?
The Webform Multiple File Upload module for Drupal 7.x is vulnerable to a cross-site scripting (XSS) issue. An attacker can exploit this flaw by uploading a file with a specially crafted filename that contains malicious JavaScript code. If the file type validation is disabled on a Webform node with a Multifile field, this can result in the execution of arbitrary scripts in the victim's browser, leading to potential unauthorized access or data breaches. Users are encouraged to apply the patch provided on GitHub or update to a secure version of the module to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Drupal 7.x
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
