← العودة للجدول
EUVD-2026-91874
📅 2026-10-03 06:31:32
🟠 High 🔥 No Vulners Vulnerability Web

📋 الوصف الكامل

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser ses

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

📡 المصدر

Vulners

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ←