CVE-2026-82451 - Formwork through 2.3.14 Stored XSS via Referer Header
CVE ID :CVE-2026-82451
Published : Aug. 29, 2026, 2:16 p.m. | 2 hours, 14 minutes ago
Description :Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 29, 2026, 2:16 p.m. | 2 hours, 14 minutes ago
Description :Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...