CVE-2024-37160
PHP vulnerability analysis and mitigation

Overview

Formwork, a flat file-based Content Management System (CMS), was found to contain a cross-site scripting (XSS) vulnerability identified as CVE-2024-37160. The vulnerability was discovered and disclosed on June 7, 2024, affecting all versions of Formwork prior to 1.13.1. This security issue allows attackers with administrator privileges to execute arbitrary web scripts by modifying site options through the /panel/options/site path (GitHub Advisory).

Technical details

The vulnerability is classified as a stored XSS with a CVSS v3.1 base score of 4.8 (Medium), with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N. The issue stems from improper neutralization of input during web page generation (CWE-79). The vulnerability specifically affects the site options functionality, where unescaped meta attributes could lead to script execution (GitHub Advisory).

Impact

The vulnerability enables persistent cross-site scripting attacks that affect visitors across all pages of the website, except for the dashboard. Once exploited, the injected malicious JavaScript executes on every page a victim visits, including about, blog, contact, or any other pages. This widespread impact makes the vulnerability particularly concerning as a single injection point leads to execution across the entire site (GitHub Advisory).

Exploitability

The vulnerability requires administrator privileges to exploit, making it somewhat limited in scope. The attack can be executed by accessing the /panel/options/site path and injecting malicious JavaScript into the description field. The persistent nature of the attack means it affects all subsequent visitors to the website (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Formwork version 1.13.1, which implements proper escaping of all metadata attributes. Users are advised to upgrade to this version or later. The fix has also been implemented in Formwork 2.x through commit f531201 (GitHub Patch).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management