Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 03 Oct 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only readWrite permission could configure Custom Head Scripts on a survey, an operation the documentation restricts to the Manage role. Because the configured scripts execute in the authenticated browser session of any user who opens the affected survey, a lower-privileged member can run arbitrary JavaScript (stored cross-site scripting) in the session of higher-privileged users. Fixed versions require Manage access to modify survey Custom Head Scripts. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-03T01:59:10.911Z
Reserved: 2026-10-03T01:59:10.142Z
Link: CVE-2026-105090
No data.
Status : Received
Published: 2026-10-03T02:17:18.370
Modified: 2026-10-03T02:17:18.370
Link: CVE-2026-105090
No data.
OpenCVE Enrichment
No data.