PT-2026-106769 · Unknown · Getformwork Formwork

·

CVE-2026-105950

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions getformwork formwork versions prior to 2.3.13
Description Remote cross site scripting is possible through the URI Sanitizer component. The issue exists in the DomSanitizer::sanitizeNodeAttribute() function within the file formwork/src/Sanitizer/DomSanitizer.php, where manipulation of the formaction argument allows for the execution of malicious scripts.
Recommendations Update to version 2.3.13.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105950
GHSA-P78Q-V3PR-P87J

Affected Products

Getformwork Formwork