SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82451

MEDIUM · CVSS 6.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects Formwork versions up to 2.3.14, allowing unauthenticated attackers to exploit a stored cross-site scripting flaw in the visit tracking feature. By crafting malicious Referer headers, attackers can inject executable markup that runs in the browsers of administrators accessing the Statistics panel, potentially compromising sensitive data or session integrity. Organizations using affected versions should prioritize patching this vulnerability to safeguard against potential attacks targeting administrative interfaces.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82451
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%

Original NVD Description

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.