rpm package
opensuse/perl-HTML-FormHandler&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/perl-HTML-FormHandler&distro=openSUSE%20Tumbleweed
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-85630 | Med | 6.1 | < 0.410.2-1.1 | 0.410.2-1.1 | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an | |
| CVE-2026-85485 | Med | 6.1 | < 0.410.2-1.1 | 0.410.2-1.1 | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escape | |
| CVE-2026-85484 | Med | 6.1 | < 0.410.2-1.1 | 0.410.2-1.1 | Sep 8, 2026 | HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other thr | |
| CVE-2026-19872 | Med | 6.1 | < 0.410.2-1.1 | 0.410.2-1.1 | Sep 8, 2026 | HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library' | |
| CVE-2022-4993 | Cri | 9.1 | < 0.410.2-1.1 | 0.410.2-1.1 | Aug 13, 2026 | HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argu |
- affected < 0.410.2-1.1fixed 0.410.2-1.1
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an
- affected < 0.410.2-1.1fixed 0.410.2-1.1
HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escape
- affected < 0.410.2-1.1fixed 0.410.2-1.1
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other thr
- affected < 0.410.2-1.1fixed 0.410.2-1.1
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library'
- affected < 0.410.2-1.1fixed 0.410.2-1.1
HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argu