CVE-2026-105950: medium-severity vulnerability in getformwork formwork
getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site scripting
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.3.13 is recommended to address this issue. The name of the patch is 729701e59c5886685c5a1d477bdc3035e41f18b1. Upgrading the affected component is advised.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Affected products
getformwork · formworkRelated CVEs — getformwork formwork
In the same product, most dangerous first.
CVE-2026-27198HIGHFormwork Improperly Manages Privileges During User CreationEPSS 0.5%CVE-2024-37160MEDIUMFormwork has a Cross-site scripting (XSS) vulnerability in Description metadataEPSS 0.5%CVE-2026-104478HIGHFormwork before 2.3.13 Path Traversal via BackupController Download and DeleteEPSS 0.4%CVE-2025-65956MEDIUMFormwork CMS Has a Stored Cross-Site Scripting (XSS) Vulnerability in Blog TagsEPSS 0.2%
References
https://github.com/getformwork/formwork/https://github.com/getformwork/formwork/commit/729701e59c5886685c5a1d477bdc3035e41f18b1https://github.com/getformwork/formwork/pull/940https://github.com/getformwork/formwork/releases/tag/2.3.13https://github.com/getformwork/formwork/security/advisories/GHSA-p78q-v3pr-p87jhttps://vuldb.com/cve/CVE-2026-105950https://vuldb.com/submit/992820https://vuldb.com/vuln/413925https://vuldb.com/vuln/413925/cti