CVE-2026-105950
Published:October 06, 2026
Updated:October 10, 2026
A security vulnerability has been detected in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.3.13 is recommended to address this issue. The name of the patch is 729701e59c5886685c5a1d477bdc3035e41f18b1. Upgrading the affected component is advised.
Affected Packages
https://github.com/getformwork/formwork.git (GITHUB):
Affected version(s) >=2.0.0-beta.2 <2.3.13Fix Suggestion:
Update to version 2.3.13getformwork/formwork (PHP):
Affected version(s) >=2.3.1 <2.3.13Fix Suggestion:
Update to version 2.3.13Related Resources (11)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.1
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
Exploit Maturity
NOT DEFINED
CVSS v3
Base Score:
3.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE
Exploit Maturity
NOT DEFINED
Weakness Type (CWE)
EPSS
Base Score:
0.24