May I please reserve a CVE ID for this exploit?

JSON file is attached. Notes on the entry:

  1. I'll add the reference to our directory entry and the Tag1 reference URL after I get the ID and we publish our writeup
  2. The vector works out to be CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N → 5.3 (Medium)
  3. Attached file is actually a JSON (but I couldn't upload that)

Additional input is very welcome. This is not yet ready to publish (still need that ref URL) but it is ready for review.

CommentFileSizeAuthor
#4 CVE-2026-0749-form-builder.txt4.34 KBaangel
Form Builder.txt3.98 KBaangel

Comments

aangel created an issue. See original summary.

greggles’s picture

Title: Form Builder CVE Request » Form Builder CVE Request - CVE-2026-0749

OK, I reserved CVE-2026-0749 for this.

greggles’s picture

Status: Needs review » Needs work

Forgot to mark needs work for publishing the page and updating the json to include the CVE id and the link.

aangel’s picture

StatusFileSize
new4.34 KB

Attached is the updated JSON:
• added CVE ID
• versions conform to D7 style
• confirmed exploit is present from >=7.x-1.0 <=7.x-1.22 and >=7.x-2.0-alpha1 <=7.x-2.0-alpha8
• however, to be consistent with the rules for advisories, I did not include the 7.x-2.x branch for this CVE update since the branch contains only alphas (Tag1 released a version for 7.x-2.x; HeroDevs did not)
• used the date Tag1 published their fix (May 14, 2025)
• added two third-party reference URLs (HeroDevs and Tag1)

greggles’s picture

Status: Needs work » Needs review

This generally LGTM. Thanks for the explanations.

greggles’s picture

Status: Needs review » Fixed

OK, I published this one. Thanks for your help.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.