PT-2026-98368 · WordPress · Jetformbuilder

CVE-2026-92212

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JetFormBuilder versions prior to 3.6.5.4
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting (XSS), a technique where malicious scripts are injected into a web page and reflected back to the user. This occurs via the jfb xss URL Query Variable parameter when used within a Calculated Field. Exploitation is possible if a targeted page hosts a form configured with both a URL Query Variable preset field and a Calculated Field that references it, requiring the attacker to trick a user into clicking a malicious link.
Recommendations Update to a version newer than 3.6.5.3. As a temporary workaround, avoid using the jfb xss parameter in Calculated Fields until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92212

Affected Products

Jetformbuilder