Stored XSS Vulnerability in HeyForm Form Builder by HeyForm
CVE-2026-35198
9CRITICAL
What is CVE-2026-35198?
Prior to version 3.0.0-rc.7, HeyForm, an open-source form builder, is vulnerable to a stored cross-site scripting (XSS) issue. This vulnerability allows low-privileged team members to inject malicious JavaScript code into the forms. When team owners view these forms, the injected script executes, creating a risk of complete account takeover through privilege escalation. Users are advised to upgrade to version 3.0.0-rc.7 or later, which addresses this vulnerability.
Affected Version(s)
heyform < 3.0.0-rc.7
