CVE-2026-45697
CRITICAL
9.8
CVSS 3.1
Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| verbb | formie | — | < 2.2.20, >= 3.0.0-beta.1, < 3.1.24 |
Weakness (CWE)
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (4)
- https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2 https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2
- https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3 https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3
- https://github.com/verbb/formie/releases/tag/2.2.20 https://github.com/verbb/formie/releases/tag/2.2.20
- https://github.com/verbb/formie/releases/tag/3.1.24 https://github.com/verbb/formie/releases/tag/3.1.24