VulnSea

HTML-FormHandler vulnerabilities

CVEs whose affected-version data names the HTML-FormHandler package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-85630Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-85485Medium· 6.1⚖ disputed
2w ago

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0…

SunlitRed Hat · HTML-FormHandlerEPSS 0.21%via NVD
CVE-2026-85484Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-19872Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into…

SunlitRed Hat · HTML-FormHandlerEPSS 0.33%via NVD
CVE-2022-4993Critical· 9.1
1mo ago

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

MidnightEPSS 0.49%via NVD
HTML-FormHandler vulnerabilities (CVEs) · VulnSea