CVE-2026-105950 | getformwork up to 2.3.12 URI Sanitizer DomSanitizer.php sanitizeNodeAttribute formaction cross site scripting (GHSA-p78q-v3pr-p87j)

SecurityVulns

A vulnerability classified as problematic was found in getformwork formwork up to 2.3.12. Impacted is the function DomSanitizer::sanitizeNodeAttribute of the file formwork/src/Sanitizer/DomSanitizer.php of the component URI Sanitizer. Such manipulation of the argument formaction leads to cross site scripting.

This vulnerability is traded as CVE-2026-105950. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More