Loading market data...
← Back to CVE feed

CVE-2026-82451

MEDIUM CVSS 6.1 View on NVD ↗

Description

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published: Aug 29, 2026 14:16 UTC Modified: Aug 29, 2026 14:16 UTC