A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Project Subscriptions

Vendors Products
Form Tools Subscribe
Form Tools Subscribe
Formtools Subscribe
Form Tools Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Formtools
Formtools form Tools
Vendors & Products Formtools
Formtools form Tools

Thu, 01 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the component Client Settings. The manipulation of the argument page_titles leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title formtools.org Form Tools Client Settings Clients.class.php updateClientSettingsTab special elements in template engine
First Time appeared Form Tools
Form Tools form Tools
Weaknesses CWE-1336
CWE-791
CPEs cpe:2.3:a:form_tools:form_tools:*:*:*:*:*:*:*:*
Vendors & Products Form Tools
Form Tools form Tools
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-01T19:10:09.527Z

Reserved: 2026-09-30T19:07:30.951Z

Link: CVE-2026-103540

cve-icon Vulnrichment

Updated: 2026-10-01T19:10:04.584Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T06:17:04.393

Modified: 2026-10-01T20:17:23.500

Link: CVE-2026-103540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:30:08Z

Weaknesses