Medium severity6.5NVD Advisory· Published Nov 26, 2025· Updated Jun 17, 2026
CVE-2025-65956
CVE-2025-65956
Description
Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed in their browser. The issue is persistent and impacts privileged administrative workflows. This issue has been patched in version 2.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getformwork/formworkPackagist | < 2.2.0 | 2.2.0 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/getformwork/formwork/commit/4abcd60ae7692b46d316f956b0b20fb85336f3b2nvdPatchWEB
- github.com/getformwork/formwork/pull/791nvdIssue TrackingPatchWEB
- github.com/getformwork/formwork/security/advisories/GHSA-7j46-f57w-76pjnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7j46-f57w-76pjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-65956ghsaADVISORY
News mentions
0No linked articles in our index yet.