CVE-2020-36960: Formalms Forma Lms
Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Forma LMS 2.3 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts into user profile first and last name fields. Attackers can craft scripts like '<script>alert(document.cookie)</script>' to execute arbitrary JavaScript when the profile is viewed by other users.
Affected products
- Formalms Forma Lms: up to and including 2.3
Published 2026-01-26. Last modified 2026-06-17.