{"id":"GHSA-vf6x-59hh-332f","aliases":[],"url":"https://o3.security/vulnerability/GHSA-vf6x-59hh-332f","summary":" Formwork has a cross-site scripting (XSS) vulnerability in Site title","details":"### Summary\n\nThe site title field at /panel/options/site/allows embedding JS tags, which can be used to attack all members of the system. This is a widespread attack and can cause significant damage if there is a considerable number of users.\n\n### Impact\n\nThe attack is widespread, leveraging what XSS can do. This will undoubtedly impact system availability.\n\n### Patches\n- [**Formwork 2.x** (aa3e9c6)](https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2) escapes site title from panel header navigation.\n\n### Details\n\nBy embedding \"<!--\", the source code can be rendered non-functional, significantly impacting system availability. However, the attacker would need admin privileges, making the attack more difficult to execute.","published":"2025-03-01T00:11:46Z","modified":"2026-02-18T23:55:33.002649Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"getformwork/formwork","fixedVersion":"2.0.0-beta.4"}],"fix":{"url":"https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2","label":"getformwork/formwork@aa3e9c6"},"references":[{"type":"WEB","url":"https://github.com/getformwork/formwork/security/advisories/GHSA-vf6x-59hh-332f"},{"type":"WEB","url":"https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2"},{"type":"PACKAGE","url":"https://github.com/getformwork/formwork"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-18T23:55:33.002649Z"}}