MEDIUMVulnerability

CVE-2026-82451

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

Properties

severity
MEDIUM
score
6.1
epss_score
0.00204
cve_id
CVE-2026-82451
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
published_at
2026-08-29T14:16:38.067
last_modified
2026-09-03T14:17:02.360
epss_percentile
0.10384

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82451 — Ninja Signal Threat Intelligence | Ninja Signal