Understanding the Cross-site Scripting Vulnerability in Drupal Simple multi step form
A security flaw has been identified in the Drupal “Simple multi step form” module. This vulnerability, known as Cross-site Scripting (XSS), occurs when the module doesn’t properly handle user input on web pages. In simple terms, this means that a malicious script could be injected into a website, potentially affecting users who visit that page. Such scripts can steal information or redirect users to harmful sites. While rated as a low-severity issue, it’s still important for website administrators to be aware of and address it.
CVE Details
- Product: Drupal Simple multi step form
- Published Date: November 18, 2025
- Severity: Low
- Status: Analyzed
Affected Products
This vulnerability impacts versions of the Drupal “Simple multi step form” module. Specifically, all versions from 0.0.0 up to, but not including, 2.0.0 are affected.
Current Status
The status of this vulnerability is “Analyzed.” This means that the issue has been thoroughly investigated and its details are understood.
Severity Level
The CVE-2025-12761 vulnerability has been assigned a “Low” severity rating with a CVSS score of 3.5. A low severity indicates that the potential impact of this vulnerability is limited. However, even low-severity issues should not be ignored, as they can sometimes be part of a larger attack chain or lead to minor disruptions or data exposure.
Possible Solutions
To mitigate this Cross-site Scripting vulnerability, users of the “Simple multi step form” module for Drupal should look for updates or patches released by the module maintainers. It is crucial to upgrade your module to version 2.0.0 or later as soon as an official fix is available. Regularly checking the official Drupal security advisories is recommended for the most current information and solution details.
References
https://www.drupal.org/sa-contrib-2025-116


