CVE-2025-26987: Dynamiapps Frontend Admin

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Reflected XSS.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.25.17.

Affected products

  • Dynamiapps Frontend Admin: before 3.25.18 (fixed in 3.25.18)

Published 2025-02-25. Last modified 2026-06-17.