PatchSiren

Jotform CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Jotform CVE published 2026-10-10

CVE-2026-40803

CVE-2026-40803 is a high-severity unauthenticated Cross Site Scripting (XSS) vulnerability in the Jotform – AI Chatbot plugin, version 3.8.2 and possibly earlier. The vulnerability has a CVSS score of 7.1 and is considered high severity.