All 9 CVE vulnerabilities found in OpnForm, with AI-generated Chinese analysis, references, and POCs.
Vendor: JhumanJ
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-11443 | JhumanJ OpnForm Forgotten Password email information exposure CWE-203 | 3.7 | Low | 2025-10-08 |
| CVE-2025-11442 | JhumanJ OpnForm API Endpoint cross-site request forgery CWE-352 | 4.3 | Medium | 2025-10-08 |
| CVE-2025-11441 | JhumanJ OpnForm HTTP Header excessive authentication CWE-307 | 3.7 | Low | 2025-10-08 |
| CVE-2025-11440 | JhumanJ OpnForm edit access control CWE-284 | 4.3 | Medium | 2025-10-08 |
| CVE-2025-11439 | JhumanJ OpnForm integrations authorization CWE-862 | 4.3 | Medium | 2025-10-08 |
| CVE-2025-11438 | JhumanJ OpnForm API Endpoint custom-domains authorization CWE-862 | 6.3 | Medium | 2025-10-08 |
| CVE-2025-11437 | JhumanJ OpnForm Form Editor forms cross site scripting CWE-79 | 2.4 | Low | 2025-10-08 |
| CVE-2025-11436 | JhumanJ OpnForm answer unrestricted upload CWE-434 | 6.3 | Medium | 2025-10-08 |
| CVE-2025-11435 | JhumanJ OpnForm submissions cross site scripting CWE-79 | 4.3 | Medium | 2025-10-08 |
All 9 known CVE vulnerabilities affecting OpnForm with full Chinese analysis, references, and POCs where available.