PatchSiren

getformwork CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM getformwork CVE published 2026-08-29

CVE-2026-82451

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-29T14:16:38.067Z and has not been modified since then. The vulnerability is a stored cross-site scripting (XSS) issue in Formwork through 2.3.14. The vulnerability occurs because the Referer header host is not properly escaped in visit tracking, allowing unauthenticated attackers to inject malicious [truncated]