An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
{ "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-200", "CWE-284" ], "github_reviewed_at": "2025-09-30T21:50:52Z", "nvd_published_at": "2025-09-30T16:15:52Z" }