FormCMS has an improper access control vulnerability in the /api/schemas/history/[schemaId] endpoint
Moderate severity
GitHub Reviewed
Published
Sep 30, 2025
to the GitHub Advisory Database
•
Updated Sep 30, 2025
Description
Published by the National Vulnerability Database
Sep 30, 2025
Published to the GitHub Advisory Database
Sep 30, 2025
Reviewed
Sep 30, 2025
Last updated
Sep 30, 2025
An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
References