CVE Feed

    Dashboard / CVE / CVE-2025-65956

    CVE-2025-65956

    Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed in their browser. The issue is persistent and impacts privileged administrative workflows. This issue has been patched in version 2.2.0.

    Published:Nov 25, 2025
    Last Modified:Dec 3, 2025
    EPS:Nov 25, 2025
    EPSS Score:0.00033
    CVSS Score:6.5

    Affected Products

    Vendor
    Formwork Project
    Product
    Formwork

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High