CVE-2016-0370: IBM Forms Experience Builder

Low severity, CVSS 2.7. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.

Affected products

  • IBM Forms Experience Builder: version 8.5.0.0 only; version 8.5.1.0 only; version 8.5.1.1 only; version 8.6.0.0 only; version 8.6.1 only; version 8.6.1.1 only; …

Published 2016-09-01. Last modified 2026-06-17.