CVE-2026-103540Medium· 6.3▾ SunlitA security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103542Medium· 4.3A flaw has been found in formtools.org Form Tools up to 3.1.1
CVE-2026-103541Medium· 6.3A vulnerability was detected in formtools.org Form Tools up to 3.1.1
CVE-2026-102771Medium· 4.7A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7
CVE-2026-75979Medium· 6.3A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta
CVE-2026-19929Medium· 6.3A vulnerability was identified in OpenBoxes up to 0.9.6
CVE-2026-102142High· 7.2A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body