Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. getformwork/formwork
  4. ›
  5. CVE-2025-65956

CVE-2025-65956: Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog Tags

November 24, 2025 (updated November 27, 2025)

Inserting unsanitized data into the blog tag field in Formwork CMS results in stored cross‑site scripting (XSS). Any user with credentials to the Formwork CMS who accesses or edits an affected blog post will have attacker‑controlled script executed in their browser. Because the issue is persistent and impacts privileged administrative workflows, the severity is elevated.

References

  • github.com/advisories/GHSA-7j46-f57w-76pj
  • github.com/getformwork/formwork
  • github.com/getformwork/formwork/commit/4abcd60ae7692b46d316f956b0b20fb85336f3b2
  • github.com/getformwork/formwork/pull/791
  • github.com/getformwork/formwork/security/advisories/GHSA-7j46-f57w-76pj
  • nvd.nist.gov/vuln/detail/CVE-2025-65956

Code Behaviors & Features

Detect and mitigate CVE-2025-65956 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.2.0

Fixed versions

  • 2.2.0

Solution

Upgrade to version 2.2.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

packagist/getformwork/formwork/CVE-2025-65956.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 04 Dec 2025 12:18:23 +0000.