CVE-2025-65956 describes a stored Cross-Site Scripting (XSS) vulnerability in Formwork CMS versions prior to 2.2.0, where unsanitized data in the blog tag field allows for script execution in a user's browser when viewing or editing an affected blog post. This medium-severity vulnerability (CVSS 5.4) requires low privileges and user interaction, potentially leading to limited confidentiality and integrity impacts on privileged administrative workflows. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.0CPE matchmatch criteria | cpe:2.3:a:formwork_project:formwork:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.