PT-2025-48034 · Formwork · Formwork

Published

2025-11-24

·

Updated

2025-11-26

·

CVE-2025-65956

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Formwork versions prior to 2.2.0
Description Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross-site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker-controlled script executed in their browser. The issue is persistent and impacts privileged administrative workflows. The vulnerable field is the blog tag field, where unsanitized data can be injected.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-65956
GHSA-7J46-F57W-76PJ

Affected Products

Formwork