Forms Project maintains a form-handling library or framework with a narrow product scope, where the observed vulnerability signal centers on cross-site scripting and related HTML-injection weaknesses that are characteristic of web-facing input-processing components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forms Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23388MEDIUM The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation. | Jun 1, 2021 | 5.3 | 19 | NO | NO |
CVE-2017-16015MEDIUM Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of fo | Jun 4, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forms Project.
Media articles that mention a CVE ID that affects a product developed by Forms Project — matched by CVE ID, not by vendor name.