{"id":"GHSA-vf6x-59hh-332f","summary":" Formwork has a cross-site scripting (XSS) vulnerability in Site title","details":"### Summary\n\nThe site title field at /panel/options/site/allows embedding JS tags, which can be used to attack all members of the system. This is a widespread attack and can cause significant damage if there is a considerable number of users.\n\n### Impact\n\nThe attack is widespread, leveraging what XSS can do. This will undoubtedly impact system availability.\n\n### Patches\n- [**Formwork 2.x** (aa3e9c6)](https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2) escapes site title from panel header navigation.\n\n### Details\n\nBy embedding \"\u003c!--\", the source code can be rendered non-functional, significantly impacting system availability. However, the attacker would need admin privileges, making the attack more difficult to execute.","modified":"2026-02-18T23:55:33.002649Z","published":"2025-03-01T00:11:46Z","database_specific":{"github_reviewed_at":"2025-03-01T00:11:46Z","nvd_published_at":null,"cwe_ids":["CWE-80"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/getformwork/formwork/security/advisories/GHSA-vf6x-59hh-332f"},{"type":"WEB","url":"https://github.com/getformwork/formwork/commit/aa3e9c684035d9e8495169fde7c57d97faa3f9a2"},{"type":"PACKAGE","url":"https://github.com/getformwork/formwork"}],"affected":[{"package":{"name":"getformwork/formwork","ecosystem":"Packagist","purl":"pkg:composer/getformwork/formwork"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-beta.3"},{"fixed":"2.0.0-beta.4"}]}],"versions":["2.0.0-beta.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-vf6x-59hh-332f/GHSA-vf6x-59hh-332f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"}]}