Cross-Site Scripting Vulnerability in Formwork by Getformwork
CVE-2026-105950
5.1MEDIUM
What is CVE-2026-105950?
A security vulnerability has been identified in the Formwork CMS, specifically within the URI Sanitizer's DomSanitizer::sanitizeNodeAttribute function. This flaw allows for the manipulation of the formaction argument, leading to potential cross-site scripting attacks, which can be executed remotely. To mitigate the risks associated with this vulnerability, it is crucial for users to upgrade to version 2.3.13, which includes necessary patches for the identified issues.
Affected Version(s)
formwork 2.3.0
formwork 2.3.1
formwork 2.3.2
