Webform 6.2.12 for Drupal 10 contains a coordinated set of 22 security fixes with advisories and one additional hardening change. Sites using a supported Webform release should update.

The release strengthens access controls around submissions, JSON:API responses, Remote Post handlers, submission exports and imports, and temporary export files. It also addresses unsafe rendering in configurable attributes, browser behaviors, uploaded-file delivery, HTTP response tokens, Entity Print output, and custom token and template formatting. Additional fixes improve file-reference validation, resource-exhaustion protection, and anti-spam handling for Webform Share.

Not every Webform installation is exposed to every issue. Some issues can affect publicly accessible forms only when particular features are configured, including file uploads, Webform Share, custom multiple-value formatting, or submission-token rendering. Many other issues require permissions to build or configure webforms, manage handlers, import or export submissions, view results, or use affected integrations such as JSON:API and Entity Print.

The release also includes one non-advisory hardening change that warns site builders when an autocomplete element exposes values collected in existing submissions. This helps administrators evaluate whether that configuration is appropriate for users who can access and submit the form.