Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Metrics
Affected Vendors & Products
References
History
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel. | |
| Title | Formwork through 2.3.14 Stored XSS via Referer Header | |
| First Time appeared |
Formwork Project
Formwork Project formwork |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Formwork Project
Formwork Project formwork |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:54.007Z
Reserved: 2026-08-29T13:22:58.240Z
Link: CVE-2026-82451
No data.
Status : Received
Published: 2026-08-29T14:16:38.067
Modified: 2026-08-29T14:16:38.067
Link: CVE-2026-82451
No data.
OpenCVE Enrichment
Updated: 2026-08-29T17:00:05Z