Formwork Project maintains a focused content management and site-building platform where its disclosed vulnerabilities cluster around web-application input handling and access control, specifically cross-site scripting and privilege management issues. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Formwork Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27198HIGH Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account cr | Feb 21, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-65956MEDIUM Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into the blog tag field results in stored cross‑site scripting (XS | Nov 26, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-24230MEDIUM A stored cross-site scripting (XSS) vulnerability in the component /formwork/panel/dashboard of Formwork v1.12.1 allows attackers to execute arbitrary web scripts or HTML via a cra | Feb 10, 2023 | 4.8 | 18 | NO | NO |
CVE-2024-37160MEDIUM Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execute arbitrary web scripts by modifying site options via /panel | Jun 7, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Formwork Project.
Media articles that mention a CVE ID that affects a product developed by Formwork Project — matched by CVE ID, not by vendor name.