CVE-2026-35198 | HeyForm up to 3.0.0-rc.6 form builder cross site scripting
A vulnerability was found in HeyForm up to 3.0.0-rc.6. It has been declared as problematic. Impacted is an unknown function of the component form builder. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-35198. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More