FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Aug 28, 2025 
          to the GitHub Advisory Database
          •
          Updated Aug 28, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Aug 28, 2025 
    
  
        Published to the GitHub Advisory Database
      Aug 28, 2025 
    
  
        Reviewed
      Aug 28, 2025 
    
  
        Last updated
      Aug 28, 2025 
    
  
FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.
References