MEDIUM 5.3 NVD

CVE-2026-82451

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated a

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

References

Published: 2026-08-29 · Source: NVD · Feed updated: 2026-08-29
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-29 via NVD.
vulnfeed aggregates 11431 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.