---
id: CVE-2026-82451
title: >-
  Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in
  visit tracking that records the Referer header host unescaped
summary: >-
  Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in
  visit tracking that records the Referer header host unescaped. Unauthenticated
  attackers can craft malicious Referer headers to inject markup that executes
  in…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-29'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:46.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82451'
references:
  - url: 'https://github.com/getformwork/formwork/releases/tag/2.3.11'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/getformwork/formwork/security/advisories/GHSA-hpgc-57cm-66pc
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/formwork-stored-xss-via-referer-header
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getformwork/formwork'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/getformwork/formwork/blob/89d1908572e55809d6ee1771f59a816494c29573/panel/views/statistics/index.php
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/formwork-through-2.3.14-stored-xss-via-referer-header
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00356
epssPercentile: 0.26656
ingestedAt: '2026-08-30T07:49:08.513Z'
vendor: getformwork
product: Formwork
affected:
  - Formwork >= 2.0.0 <= 2.3.10
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-02T18:02:28.558485Z'
---

## Overview

Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
