{"id":"CVE-2026-35198","title":"HeyForm is an open-source form builder","summary":"HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner…","severity":"critical","cvss":9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-79"],"published":"2026-07-20","updated":"2026-08-21","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-35198","references":[{"url":"https://github.com/heyform/heyform/commit/cc97d27a57ae400fec23abf5dcf6f9533c3b5db3","label":"security-advisories@github.com"},{"url":"https://github.com/heyform/heyform/security/advisories/GHSA-chmm-jqpm-3pwx","label":"security-advisories@github.com"},{"url":"https://vokecyber.com/research/cve-2026-35198-heyform-stored-xss","label":"security-advisories@github.com"},{"url":"https://github.com/heyform/heyform/security/advisories/GHSA-chmm-jqpm-3pwx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.0049,"epssPercentile":0.4121,"ingestedAt":"2026-08-22T13:32:35.490Z","slug":"CVE-2026-35198","body":"## Overview\n\nHeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete account takeover through privilege escalation. Version 3.0.0-rc.7 contains a patch for the issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":49.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}