CVE-2018-6354: Formspree

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

templates/forms/thanks.html in Formspree before 2018-01-23 allows XSS related to the _next parameter.

Affected products

  • Formspree Formspree: before 2018-01-23 (fixed in 2018-01-23)

Published 2018-01-27. Last modified 2026-06-17.