CVE-2020-13423: Form Builder For Magento 2 Project Form Builder For Magento 2

Medium severity, CVSS 4.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.

Affected products

Published 2020-06-29. Last modified 2026-06-17.