Server-Side Template Injection Vulnerability in FormTools by formtools.org
CVE-2026-103540

5.3MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-103540?

A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the improper handling of the 'page_titles' argument, resulting in insufficient protection against the manipulation of special elements typically utilized by a template engine. Given that this vulnerability can be exploited remotely, it poses a significant risk to users. The project was notified of this issue early via an issue report but has yet to issue a response. Appropriate measures should be taken to secure affected instances.

Affected Version(s)

Form Tools 3.1.0

Form Tools 3.1.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

wenyouwen (VulDB User)
VulDB CNA Team
.