CVE-2026-103540 | formtools.org Form Tools up to 3.1.1 Client Settings Clients.class.php updateClientSettingsTab page_titles special elements in template engine (Issue 956)
A vulnerability was found in formtools.org Form Tools up to 3.1.1. It has been rated as critical. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2026-103540. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More