Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 29 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel. | |
| Title | Formwork through 2.3.14 Stored XSS via Referer Header | |
| First Time appeared |
Formwork Project
Formwork Project formwork |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Formwork Project
Formwork Project formwork |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T13:47:54.007Z
Reserved: 2026-08-29T13:22:58.240Z
Link: CVE-2026-82451
No data.
Status : Received
Published: 2026-08-29T14:16:38.067
Modified: 2026-08-29T14:16:38.067
Link: CVE-2026-82451
No data.
OpenCVE Enrichment
Updated: 2026-08-29T16:00:03Z
Weaknesses