Unknown · Getformwork Formwork · CVE-2026-105950
**Name of the Vulnerable Software and Affected Versions**
getformwork formwork versions prior to 2.3.13
**Description**
Remote cross site scripting is possible through the URI Sanitizer component. The issue exists in the `DomSanitizer::sanitizeNodeAttribute()` function within the file formwork/src/Sanitizer/DomSanitizer.php, where manipulation of the `formaction` argument allows for the execution of malicious scripts.
**Recommendations**
Update to version 2.3.13.