Access Control Bypass Affecting formcms package, versions [,0.5.5)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-FORMCMS-13292376
  • published6 Oct 2025
  • disclosed30 Sept 2025
  • creditKuycheu Kung KKC73

Introduced: 30 Sep 2025

NewCVE-2025-55797  (opens in a new tab)
CWE-200  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade FormCMS to version 0.5.5 or higher.

Overview

FormCMS is a FormCMS is an open-source Content Management System designed to simplify and accelerate web development workflows for CMS projects and general web applications. It streamlines data modeling, backend development, and frontend design, making them as intuitive as filling out a form. With a focus on fostering user engagement, FormCMS provides robust social features alongside powerful tools for data management, API development, and dynamic page creation.

Affected versions of this package are vulnerable to Access Control Bypass via the /api/schemas/history/[schemaId] endpoint. An attacker can retrieve historical schema data by sending unauthenticated requests with a valid or guessed schemaId.

CVSS Base Scores

version 4.0
version 3.1