FormCMS
NuGet2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting FormCMSpage 1 of 1
- CVE-2025-55797MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.5.52025-09-30
vulnerable: 0.4.4 ... 0.5.4 (11 versions)
An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
- CVE-2025-56236MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.5.72025-08-28
vulnerable: 0.4.4 ... 0.5.6 (13 versions)
FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged us…
Check whether FormCMS is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for FormCMS CVEs against the assets you own.
Start Free Scan →