npm package reportIs @payloadcms/plugin-form-builder safe?
1 known vulnerability, worst severity CRITICAL.
// reach0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
epsschance of exploitation in 30 days
xyz scoreCyberXYZ composite out of 10
fig. 01 — GHSA-r488-j9vj-wx3q, the advisory selected below
// 1 advisories
// impactA vulnerability in @payloadcms/plugin-form-builder in versions = 3.90.0 or >= 4.0.0-canary.34.
// cvss v3.1 vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Checked 2026-10-08 at 00:18 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.