CVE-2025-31080Cross-site Scripting in Software LLC Html Forms

Severity
7.3HIGH
No vector
EPSS
0.1%
top 66.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms html-forms allows Stored XSS.This issue affects HTML Forms: from n/a through <= 1.5.1.

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
WordPress HTML Forms plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability2025-04-01
GHSA
GHSA-pmm6-x9mw-vxqc: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Software LLC HTML Forms allows Stored XSS2025-04-01

📋Vendor Advisories

1
Microsoft
Xorg-x11-server: heap buffer overread/data leakage in procxigetselectedevents2024-04-09
CVE-2025-31080 — Cross-site Scripting | cvebase