CVE-2026-0749: Silence Form Builder

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Form Builder allows Cross-Site Scripting (XSS).This issue affects Drupal: from 7.X-1.0 through 7.X-1.22.

Affected products

  • Silence Form Builder: from 7.x-1.0, up to and including 7.x-1.22

Published 2026-01-28. Last modified 2026-06-17.