Stored XSS Vulnerability in Formwork CMS Prior to Version 2.2.0
CVE-2025-65956

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 November 2025

What is CVE-2025-65956?

Prior to version 2.2.0, Formwork CMS is susceptible to a stored cross-site scripting vulnerability that allows attackers to inject unsanitized data into the blog tag field. When a user with administrative privileges accesses or edits an affected blog post, malicious scripts controlled by the attacker can be executed in their browser. This persistent vulnerability compromises vital administrative tasks and user safety, emphasizing the need for an immediate upgrade to version 2.2.0, where the issue has been addressed.

Affected Version(s)

formwork < 2.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.