forms vulnerabilities
CVEs whose affected-version data names the forms package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-56291Critical· 9.8CISA KEV0dayPoCThe Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
▾ Hadalbalbooa · formsEPSS 15%via NVD
CVE-2026-45543Medium· 5.3Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the affected form. The scope is limited to u…
▾ Sunlitnextcloud · formsEPSS 0.27%via NVD