Vulnerabilidades en heyform
4 resultadosCVE-2026-45797MEDIUMHeyForm Vulnerable to Stored XSS via Unauthenticated SVG File UploadEPSS 0.4%CVE-2026-63429HIGHHeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form contextEPSS 0.3%CVE-2026-63428MEDIUMHeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field setEPSS 0.2%CVE-2026-35198CRITICALHeyForm vulnerable to stored XSS via form field titlesEPSS 0.2%