Security releaseUmbraco backoffice advisory CVE-2026-41205 — managed clients already patched.Read the advisory
websitesupport.io
All articles
SecurityWebflowAdvisory

Webflow tightens Marketplace review after malicious embed apps found injecting scripts

A wave of third-party Webflow Marketplace apps were found injecting obfuscated scripts via legitimate-looking embeds. Here's what happened and what to check on your own site.

W
WebsiteSupport.io Security Team
8 Aug 20264 min read
APPMARKETPLACE · EMBED AUDIT
Advisory

Multiple Webflow Marketplace apps · Obfuscated third-party scripts · Audit installed embeds and review your CSP.

Over the past few weeks, security researchers and Webflow's own trust and safety team identified a cluster of third-party Marketplace apps — mostly in the chat widget, personalisation and A/B-testing categories — that were injecting obfuscated scripts beyond what their listed permissions described. Webflow has since tightened its App Marketplace review process for anything that touches the DOM.

What happened

Several apps published to the Marketplace under legitimate-looking listings were found, after installation, to load additional third-party scripts not disclosed at install time — in some cases scripts capable of capturing form input or injecting further embeds dynamically. Webflow removed the affected apps and published a review-process update requiring stricter static analysis of any app requesting DOM or script-injection permissions.

Who this affects

  • Sites with chat widget, personalisation or A/B-testing apps installed from the Marketplace before this review update
  • Sites with custom code embeds copied from third-party snippets rather than the Marketplace directly
  • Agencies managing multiple client Webflow sites, where the same app may be installed across a fleet

What you should do

  • Review every installed Marketplace app and custom embed — remove anything you don't actively use
  • Check browser network activity on a staging copy of your site for unexpected third-party script origins
  • Add or tighten a Content Security Policy to restrict which script origins your site will execute
  • If you manage a fleet, audit all sites rather than assuming the issue is isolated to one

How we handled this for managed clients

We ran an embed audit across every managed Webflow client as soon as the affected app list was published, cross-referencing installed apps and custom embeds against the disclosed list. No managed client was running an affected app, but two had unrelated legacy embeds removed as a precaution. No action is needed if you're on a WebsiteSupport.io Webflow retainer.

Not sure what's actually installed on your Webflow site?

We can run a one-off embed and script audit and tell you plainly what's there, what it does, and what it's safe to remove.

Talk to us about Webflow support

Stay ahead of the next release

Security alerts, platform updates and industry analysis — straight to your inbox.

We respect your privacy and only send essential updates.