CVE-2026-85630
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the field attributes or embed JavaScript in rendered pages. For example, the RadioGroup widget uses the process_attrs method via the render_option and wrap_radio methods.
Scoring
- CVSS base score
- 0
- CWE
- CWE-79
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Weakness type
Related vulnerabilities
- CVE-2026-87923 — Rizwan17 inventory-management-system List DBOperation.php cross site scripting
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-18147 — Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url
- CVE-2026-86772 — Snipe-IT 8.6.3 Stored XSS via Department Names
- CVE-2026-87814 — SiYuan before v3.8.2 Stored XSS via Asset Preview
- CVE-2026-87813 — SiYuan before v3.8.2 Stored XSS via unescaped asset filenames
- CVE-2026-87812 — SiYuan before v3.8.2 Stored XSS via Bazaar iconURL