CVE-2026-47266
published 2026-05-29CVE-2026-47266: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or…
PriorityP349high8.7CVSS 4.0
AVNACLATNPRNUINVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.31%
24.2th percentile
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| verbb | formie | < 2.2.21 | 2.2.21 |
| verbb | formie | — | — |
| verbb | formie | >= 0 < 2.2.21 | 2.2.21 |
| verbb | formie | >= 3.0.0 < 3.1.26 | 3.1.26 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
formie's unauthenticated front-end submission editing can overwrite existing submissions
ghsa·2026-05-29
CVE-2026-47266 [HIGH] CWE-639 formie's unauthenticated front-end submission editing can overwrite existing submissions
formie's unauthenticated front-end submission editing can overwrite existing submissions
### Impact
Unauthenticated users could modify existing submissions by posting a known or guessed submission ID to `formie/submissions/save-submission`.
### Patches
[2.2.21](https://github.com/verbb/formie/releases/tag/2.2.21), [3.1.26](https://github.com/verbb/formie/releases/tag/3.1.26)
### Workarounds
Block unauthenticated access to `actions/formie/submissions/save-submission`, or disable/customize front-end submission editing until patched.
### Credit
formie extends many thanks to:
- Florian (Cyber Security Engineer, arcade solutions ag)
- Contact: [[email protected]](mailto:[email protected])
VulDB
verbb formie up to 2.2.20/3.1.25 save-submission authorization
vuldb·2026-05-29·CVSS 8.7
CVE-2026-47266 [HIGH] verbb formie up to 2.2.20/3.1.25 save-submission authorization
A vulnerability classified as problematic has been found in verbb formie up to 2.2.20/3.1.25. The affected element is an unknown function of the file formie/submissions/save-submission. The manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-47266. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-29
Published