CVE-2026-105950: fallo de gravedad media en getformwork formwork
getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site scripting
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.3.13 is recommended to address this issue. The name of the patch is 729701e59c5886685c5a1d477bdc3035e41f18b1. Upgrading the affected component is advised.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Productos afectados
getformwork · formworkCVEs relacionadas — getformwork formwork
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-27198HIGHFormwork Improperly Manages Privileges During User CreationEPSS 0.5%CVE-2024-37160MEDIUMFormwork has a Cross-site scripting (XSS) vulnerability in Description metadataEPSS 0.5%CVE-2026-104478HIGHFormwork before 2.3.13 Path Traversal via BackupController Download and DeleteEPSS 0.4%CVE-2025-65956MEDIUMFormwork CMS Has a Stored Cross-Site Scripting (XSS) Vulnerability in Blog TagsEPSS 0.2%
Referencias
https://github.com/getformwork/formwork/https://github.com/getformwork/formwork/commit/729701e59c5886685c5a1d477bdc3035e41f18b1https://github.com/getformwork/formwork/pull/940https://github.com/getformwork/formwork/releases/tag/2.3.13https://github.com/getformwork/formwork/security/advisories/GHSA-p78q-v3pr-p87jhttps://vuldb.com/cve/CVE-2026-105950https://vuldb.com/submit/992820https://vuldb.com/vuln/413925https://vuldb.com/vuln/413925/cti