CVE-2026-82451 Overview
CVE-2026-82451 is a stored cross-site scripting vulnerability in Formwork, a flat-file content management system, affecting versions before 2.3.11. The flaw resides in the visit tracking component, which records the Referer header host without proper output escaping. Unauthenticated attackers can send HTTP requests with crafted Referer headers containing malicious markup. When an administrator later views the Statistics panel, the injected payload executes in the administrator's browser session. The vulnerability is tracked as CWE-79 and was addressed in the Formwork 2.3.11 release.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript into the administrator Statistics panel, enabling session hijacking, credential theft, or arbitrary actions within the admin context.
Affected Products
- Formwork content management system versions prior to 2.3.11
- Deployments exposing the visit tracking and Statistics panel features
- Administrative interfaces accessed by authenticated site operators
Discovery Timeline
- 2026-08-29 - CVE-2026-82451 published to NVD
- 2026-09-03 - Last updated in NVD database
Technical Details for CVE-2026-82451
Vulnerability Analysis
Formwork's visit tracking module logs incoming HTTP request metadata, including the host portion of the Referer header, to power the administrator Statistics panel. The application stores this attacker-controlled value without HTML-encoding it and renders it back into the admin dashboard as raw markup. Because the injection point is reached before authentication, any anonymous visitor can populate the analytics store with arbitrary payloads. When an administrator opens the Statistics view, the browser parses and executes the injected script under the admin origin.
Root Cause
The root cause is missing output encoding on user-controlled input, as classified by CWE-79. The Referer header host string is treated as trusted display data instead of untrusted input. Formwork's template layer emits the value directly into the Statistics panel HTML, allowing tag and attribute injection.
Attack Vector
Exploitation requires no authentication and no privileges on the target Formwork installation. An attacker issues an HTTP request to any tracked page while setting a Referer header that contains HTML or JavaScript within the host component. The payload is persisted server-side in the visit log. Exploitation completes when an administrator subsequently loads the Statistics panel, satisfying the passive user-interaction requirement reflected in the CVSS vector. Successful attacks can perform actions in the admin context, steal session cookies not marked HttpOnly, or pivot to further site modification.
No public proof-of-concept code has been verified. Refer to the GitHub Security Advisory GHSA-hpgc-57cm-66pc and the VulnCheck advisory on Formwork stored XSS for technical details.
Detection Methods for CVE-2026-82451
Indicators of Compromise
- HTTP requests with Referer headers containing <script>, onerror=, onload=, or other HTML tag or event-handler syntax in the host portion.
- Entries in Formwork's visit tracking store or Statistics panel data files containing non-alphanumeric characters outside valid hostname syntax.
- Outbound requests from administrator browsers to attacker-controlled domains shortly after loading the Statistics panel.
Detection Strategies
- Inspect reverse-proxy or web server access logs for malformed Referer header values that include angle brackets, quotes, or JavaScript keywords.
- Review Formwork visit log files on disk for stored payloads matching HTML or script markup.
- Deploy web application firewall rules that flag Referer headers failing RFC 3986 host validation.
Monitoring Recommendations
- Alert on administrative sessions issuing unexpected cross-origin requests immediately after Statistics panel access.
- Monitor file integrity on Formwork data directories for anomalous writes to visit tracking storage.
- Track failed Content Security Policy violations reported by admin browsers as a signal of injected script execution attempts.
How to Mitigate CVE-2026-82451
Immediate Actions Required
- Upgrade all Formwork instances to version 2.3.11 or later without delay.
- Purge existing visit tracking data that may already contain stored payloads before administrators reopen the Statistics panel.
- Rotate administrator credentials and invalidate active admin sessions if exploitation is suspected.
Patch Information
The maintainers fixed the issue in Formwork 2.3.11 by escaping the Referer host value before storage and rendering. Administrators should apply the update by pulling the tagged release or updating via their deployment pipeline. The full remediation guidance is available in GHSA-hpgc-57cm-66pc.
Workarounds
- Disable the visit tracking feature until the upgrade to 2.3.11 can be deployed.
- Configure the fronting web server or reverse proxy to strip or validate the Referer header before it reaches Formwork.
- Enforce a strict Content Security Policy on the admin interface that disallows inline scripts and unknown script sources.
# Example nginx rule to drop Referer headers containing HTML metacharacters
map $http_referer $safe_referer {
default $http_referer;
"~[<>\"']" "";
}
server {
location / {
proxy_set_header Referer $safe_referer;
proxy_pass http://formwork_backend;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.