THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82451 (MEDIUM 6.1) — Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the S

[NVD] CVE-2026-82451 (MEDIUM 6.1) — Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the S

mednvdPublished 2026-08-29

CVE-2026-82451 CVSS: 6.1 MEDIUM Published: 2026-08-29T14:16:38.067

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82451