CVE-2026-82451: Stored Cross-Site Scripting in Formwork via Referer Header
A stored cross-site scripting (XSS) vulnerability exists in Formwork versions up to 2.3.14. The vulnerability is triggered by an unauthenticated attacker crafting a malicious Referer header, which is then stored and executed in the administrator's browser when viewing the Statistics panel. The CVSS score for this vulnerability is 6.1, indicating a medium severity. Organizations using Formwork should update to a patched version immediately.