CVE-2026-45697
published 2026-05-29CVE-2026-45697: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.47%
40.2th percentile
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| verbb | formie | < 2.2.20 | 2.2.20 |
| verbb | formie | — | — |
| verbb | formie | >= 0 < 2.2.20 | 2.2.20 |
| verbb | formie | >= 3.0.0-beta.1 < 3.1.24 | 3.1.24 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
verbb formie up to 2.2.19/3.1.23 code injection
vuldb·2026-05-29·CVSS 9.8
CVE-2026-45697 [CRITICAL] verbb formie up to 2.2.19/3.1.23 code injection
A vulnerability marked as critical has been reported in verbb formie up to 2.2.19/3.1.23. This issue affects some unknown processing. Performing a manipulation results in code injection.
This vulnerability is identified as CVE-2026-45697. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
Formie: Pre-authenticated server-side template injection in Hidden fields
ghsa·2026-05-18
CVE-2026-45697 [CRITICAL] CWE-1336 Formie: Pre-authenticated server-side template injection in Hidden fields
Formie: Pre-authenticated server-side template injection in Hidden fields
### Impact
- Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior).
- Sites with public Formie forms that include at least one Hidden field with that configuration.
- No CP login for the reported chain.
### Patches
- [2.2.20](https://github.com/verbb/formie/releases/tag/2.2.20), [3.1.24](https://github.com/verbb/formie/releases/tag/3.1.24)
### Workarounds
- Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible
- Otherwise, upgrade to patched versions
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-29
Published