← العودة للجدول
CVE-2026-105090
CVE-2026-105090 — Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level C
📅 2026-10-03
🟠 High 🔥 No NVD Vulnerability Web

📋 الوصف الكامل

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser ses

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-105090

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-105090 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←