Junglewise Threat Intelligence

CVE-2026-82451: Formwork stored cross-site scripting in visit tracking

CVE-2026-82451 · Severity: medium · CVSS 6.1 · Published 2026-08-29

Executive brief

Formwork is a database-free CMS used to build dynamic websites. The platform's visit statistics feature fails to properly escape data from HTTP Referer headers, allowing attackers to inject malicious code that executes in administrators' browsers when they view the Statistics panel. An attacker can exploit this by sending requests with crafted Referer headers to compromise administrator accounts or gain access to sensitive site data.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Formwork's visit tracking component. The vulnerable code records the Referer header host value directly without HTML escaping, allowing unauthenticated attackers to inject arbitrary markup. An attacker can craft malicious HTTP requests with XSS payloads in the Referer header; when stored in the statistics database, the injected script executes in the context of any administrator viewing the Statistics panel. No authentication is required to trigger the vulnerability, but successful exploitation requires an administrator to view the affected panel. The vulnerability was patched in version 2.3.11, which added proper input validation for visitor statistics sources.

Affected products

  • Formwork Formwork before 2.3.11

Timeline

  • 2026-08-29: disclosed
  • 2026-08-12: patched: Fixed in version 2.3.11 with proper validation of statistics visitor source

References