Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Forma — Vulnerabilities & Security Advisories 7

Browse all 7 CVE security advisories affecting Forma. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Forma is a web-based platform primarily used for marketing automation and customer engagement, enabling businesses to manage campaigns and analyze customer interactions. Historically, Forma has been vulnerable to several security issues, including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities, as evidenced by its seven recorded CVEs. The platform's security posture has been characterized by vulnerabilities in input validation and access control mechanisms. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests ongoing challenges in secure coding practices, particularly in handling user inputs and managing authentication processes.

Found 1 results / 7 Clear Filters
Top products by Forma: Forma LMS E-Learning Suite
CVE ID Title CVSS Severity Published
CVE-2020-36998 forma.lms The E-Learning Suite 2.3.0.2 - Persistent Cross-Site Scripting — E-Learning Suite CWE-79 6.4 Medium 2026-01-30

This page lists every published CVE security advisory associated with Forma. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.