CVE-2020-36960: Formalms Forma Lms

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.

Affected products

  • Formalms Forma Lms: up to and including 2.3

Published 2026-01-26. Last modified 2026-06-17.