Stored XSS Affecting formcms package, versions [,0.5.7)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Stored XSS vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-FORMCMS-12304082
  • published2 Sept 2025
  • disclosed28 Aug 2025
  • creditKuycheu Kung

Introduced: 28 Aug 2025

NewCVE-2025-56236  (opens in a new tab)
CWE-434  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade FormCMS to version 0.5.7 or higher.

Overview

FormCMS is a FormCMS is an open-source Content Management System designed to simplify and accelerate web development workflows for CMS projects and general web applications. It streamlines data modeling, backend development, and frontend design, making them as intuitive as filling out a form. With a focus on fostering user engagement, FormCMS provides robust social features alongside powerful tools for data management, API development, and dynamic page creation.

Affected versions of this package are vulnerable to Stored XSS via the /api/profile/avatar endpoint. An attacker who can convince a user to follow a link to a public URL can execute arbitrary JavaScript code in the browser of privileged users by uploading a malicious .html file.

CVSS Base Scores

version 4.0
version 3.1