CVE-2025-55797: FormCMS has an improper access control vulnerability in the /api/schemas/history/[schemaId] endpoint
An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-55797 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →