๐Ÿ” CVE Alert

CVE-2026-45797

UNKNOWN 0.0

HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored in the static assets directory and served with `Content-Type: image/svg+xml` by Express's serve-static middleware, allowing an attacker to achieve stored cross-site scripting (XSS) on the heyform domain without any authentication. Version 3.0.0-rc.7 contains a patch for the issue.

CWE CWE-79 CWE-434
Vendor heyform
Product heyform
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for heyform heyform

Be the first to know when new unknown vulnerabilities affecting heyform heyform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

heyform / heyform
< 3.0.0-rc.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/heyform/heyform/security/advisories/GHSA-m94h-jxvc-hhch github.com: https://github.com/heyform/heyform/commit/144240e5545d10fd9e120d05ccb402a6d7064674