CVE-2025-32199: Eyale-Vc Contact Form Builder By Vcita

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyale-vc Contact Form Builder by vcita contact-form-with-a-meeting-scheduler-by-vcita allows DOM-Based XSS.This issue affects Contact Form Builder by vcita: from n/a through <= 4.10.2.

Affected products

  • Eyale-Vc Contact Form Builder By Vcita: up to and including 4.10.2

Published 2025-04-10. Last modified 2026-06-17.