CVE-2026-82451

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 14:16

Updated : 2026-09-03 14:17


NVD link : CVE-2026-82451

Mitre link : CVE-2026-82451

CVE.ORG link : CVE-2026-82451


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')