CVE-2017-16015

MEDIUM

forms < 1.3.0 - Cross-Site Scripting via Improper HTML Escaping

Title source: llm
STIX 2.1

Description

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0085
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79 CWE-80
Status published
Products (2)
forms_project/forms < 1.3.0
npm/forms 0 - 1.3.0npm
Published Jun 04, 2018
Tracked Since Feb 18, 2026