CVE-2025-10316 LOW

CVE-2025-10316: Cross-Site Scripting in extension "Form to Database" (form_to_database)

Vendor Typo3
Product Extension "Form to Database" (form_to_database)
Weakness CWE-79 · XSS
Published September 16, 2025
Last update September 16, 2025

CVSS base score

2.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before 3.2.2, from 4.0.0 before 4.2.3, from 5.0.0 before 5.0.2.

Key dates

02Disclosure timeline

September 16, 2025 CVE published
September 16, 2025 Record updated