CVE-2026-105950: falha de média gravidade em getformwork formwork
getformwork URI Sanitizer DomSanitizer.php sanitizeNodeAttribute cross site scripting
Publicada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.1epss 0.2%
probabilidade de exploração
0.2%top 86% das CVEs
exploração observada
nãonenhuma fonte reporta
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.3.13 is recommended to address this issue. The name of the patch is 729701e59c5886685c5a1d477bdc3035e41f18b1. Upgrading the affected component is advised.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Produtos afetados
getformwork · formworkCVEs relacionadas — getformwork formwork
No mesmo produto, das mais perigosas para as menos.
CVE-2026-27198HIGHFormwork Improperly Manages Privileges During User CreationEPSS 0.5%CVE-2024-37160MEDIUMFormwork has a Cross-site scripting (XSS) vulnerability in Description metadataEPSS 0.5%CVE-2026-104478HIGHFormwork before 2.3.13 Path Traversal via BackupController Download and DeleteEPSS 0.4%CVE-2025-65956MEDIUMFormwork CMS Has a Stored Cross-Site Scripting (XSS) Vulnerability in Blog TagsEPSS 0.2%
Referências
https://github.com/getformwork/formwork/https://github.com/getformwork/formwork/commit/729701e59c5886685c5a1d477bdc3035e41f18b1https://github.com/getformwork/formwork/pull/940https://github.com/getformwork/formwork/releases/tag/2.3.13https://github.com/getformwork/formwork/security/advisories/GHSA-p78q-v3pr-p87jhttps://vuldb.com/cve/CVE-2026-105950https://vuldb.com/submit/992820https://vuldb.com/vuln/413925https://vuldb.com/vuln/413925/cti