Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-56358

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inject XSS payloads that execute persistently for all form visitors, enabling form hijacking and phishing attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 3.8%
CVSS Severity
CVSS v3 Score 5.4


Contact Us

Shodan ® - All rights reserved