Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Formbricks
Formbricks formbricks |
|
| Vendors & Products |
Formbricks
Formbricks formbricks |
Sat, 03 Oct 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS via Custom Head Scripts in Formbricks |
Sat, 03 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-03T01:59:10.911Z
Reserved: 2026-10-03T01:59:10.142Z
Link: CVE-2026-105090
No data.
Status : Received
Published: 2026-10-03T02:17:18.370
Modified: 2026-10-03T02:17:18.370
Link: CVE-2026-105090
No data.
OpenCVE Enrichment
Updated: 2026-10-03T05:00:13Z
