CVE-2026-82451
Received
Received - Intake
Stored XSS in Formwork Visit Tracking via Unescaped Referer Header
Vulnerability report for CVE-2026-82451, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-29
Last updated on: 2026-08-29
Assigner: VulnCheck
Description
Description
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| getformwork | formwork | to 2.3.14 (inc) |
| getformwork | formwork | From 2.0.0 (inc) to 2.3.10 (inc) |
| getformwork | formwork | to 2.3.11 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |