OpnForm是Julien Nahum个人开发者的一个表单生成器。 OpnForm 1.9.3及之前版本存在安全漏洞,该漏洞源于HTTP Header Handler组件中参数X-Forwarded-For操作不当,可能导致过度身份验证尝试限制不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11436 | 6.3 MEDIUM | JhumanJ OpnForm answer unrestricted upload |
| CVE-2025-11438 | 6.3 MEDIUM | JhumanJ OpnForm API Endpoint custom-domains authorization |
| CVE-2025-11435 | 4.3 MEDIUM | JhumanJ OpnForm submissions cross site scripting |
| CVE-2025-11442 | 4.3 MEDIUM | JhumanJ OpnForm API Endpoint cross-site request forgery |
| CVE-2025-11439 | 4.3 MEDIUM | JhumanJ OpnForm integrations authorization |
| CVE-2025-11440 | 4.3 MEDIUM | JhumanJ OpnForm edit access control |
| CVE-2025-11443 | 3.7 LOW | JhumanJ OpnForm Forgotten Password email information exposure |
| CVE-2025-11437 | 2.4 LOW | JhumanJ OpnForm Form Editor forms cross site scripting |
No comments yet