Medium severity6.1NVD Advisory· Published Aug 29, 2026
CVE-2026-82451
CVE-2026-82451
Description
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.