opnform vulnerabilities
CVEs whose affected-version data names the opnform package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-75106Critical· 9.1PoCOpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full sub…
CVE-2025-11443Low· 3.7A weakness has been identified in JhumanJ OpnForm up to 1.9.3
A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/password/email of the component Forgotten Password Handler. This manipulation causes information exposure through discrepanc…
CVE-2025-11442Medium· 4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3
A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the component API Endpoint. The manipulation results in cross-site request forgery. The attack may be performed from remot…
CVE-2025-11441Low· 3.7A vulnerability was identified in JhumanJ OpnForm up to 1.9.3
A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive …
CVE-2025-11440Medium· 4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3
A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Executing manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publ…
CVE-2025-11439Medium· 4.3A vulnerability was found in JhumanJ OpnForm up to 1.9.3
A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible.…
CVE-2025-11438Medium· 6.3A vulnerability has been found in JhumanJ OpnForm up to 1.9.3
A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launche…
CVE-2025-11437Low· 2.4A flaw has been found in JhumanJ OpnForm up to 1.9.3
A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploi…
CVE-2025-11436Medium· 6.3A vulnerability was detected in JhumanJ OpnForm up to 1.9.3
A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is n…
CVE-2025-11435Medium· 4.3A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3
A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initia…