---
id: CVE-2025-11435
title: A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3
summary: >-
  A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3.
  Affected by this vulnerability is an unknown functionality of the file
  /show/submissions. The manipulation leads to cross site scripting. The attack
  can be initia…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: jhumanj
product: opnform
affected:
  - opnform <= 1.9.3
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11435'
references:
  - url: >-
      https://docs.google.com/document/d/1GUjJA9vUbsXUngAv6ySsbCIhVynf8_djardLZYEDOe0/edit?usp=sharing
    label: cna@vuldb.com
  - url: >-
      https://github.com/JhumanJ/OpnForm/pull/900/commits/a2af1184e53953afa8cb052f4055f288adcaa608
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327372'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327372'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.666876'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00395
epssPercentile: 0.31547
ingestedAt: '2026-10-08T13:42:54.996Z'
---

## Overview

A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is a2af1184e53953afa8cb052f4055f288adcaa608. To fix this issue, it is recommended to deploy a patch.

## Affected

- `opnform <= 1.9.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
