An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed.
{
"github_reviewed_at": "2025-09-30T21:50:52Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-200",
"CWE-284"
],
"nvd_published_at": "2025-09-30T16:15:52Z",
"severity": "MODERATE"
}