MEDIUM 5.3 NVD
CVE-2026-82451
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated a
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
References
- https://github.com/getformwork/formwork
- https://github.com/getformwork/formwork/blob/89d1908572e55809d6ee1771f59a816494c29573/pane
- https://github.com/getformwork/formwork/security/advisories/GHSA-hpgc-57cm-66pc
- https://www.vulncheck.com/advisories/formwork-through-2.3.14-stored-xss-via-referer-header
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-29 via NVD.
vulnfeed aggregates 11431 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.