Intel

AIKIDO-2025-10783

drupal/simple_multistep is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-12761 Published Nov 10, 2025

50

Medium Risk

This Affects:

PHPdrupal/simple_multistep
1.0.0 - 1.0.0
Fixed in 2.0.0
Are you affected? Scan for Free

TL;DR

This module allows converting any entity form into a simple multi-step form. It fails to properly sanitize certain user-supplied text, leading to a cross-site scripting (XSS) vulnerability. Exploitation of this issue is limited to users with the “administer node form display” permission.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/simple_multistep is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.0.0.

How to fix this

Upgrade the drupal/simple_multistep library to the patch version.