Verbb Formie vulnerabilities
9 known vulnerabilities affecting verbb/formie.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-52889P2CRITICALCVSS 9.8fixed in 3.1.272026-08-19
CVE-2026-52889 [CRITICAL] CWE-1336 CVE-2026-52889: Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An unauthenticated attacker can place Twig s
ghsanvd
CVE-2026-76086P2HIGHCVSS 8.5fixed in 2.2.23v>= 3.0.0, < 3.1.312026-09-23
CVE-2026-76086 [HIGH] CWE-862 CVE-2026-76086: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integra
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace
ghsanvd
CVE-2026-45697P3CRITICALCVSS 9.8fixed in 2.2.20v>= 3.0.0-beta.1, < 3.1.242026-05-29
CVE-2026-45697 [CRITICAL] CWE-94 CVE-2026-45697: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users c
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability
ghsanvd
CVE-2026-47266P3HIGHCVSS 8.7fixed in 2.2.23v>= 3.0.0, < 3.1.312026-05-29
CVE-2026-47266 [HIGH] CWE-639 CVE-2026-47266: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users c
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.
ghsanvd
CVE-2026-76089P3HIGHCVSS 7.7fixed in 2.2.23v>= 3.0.0, < 3.1.312026-09-23
CVE-2026-76089 [HIGH] CWE-200 CVE-2026-76089: Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-no
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invo
ghsanvd
CVE-2026-76087P3HIGH≥ 3.0.0, < 3.1.31≥ 0, < 2.2.232026-09-23
CVE-2026-76087 [HIGH] CWE-639 Formie: Unauthenticated users can overwrite incomplete submissions via submit action
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
### Impact
The anonymous front-end action `formie/submissions/submit` (`SubmissionsController::actionSubmit`) trusted a client-supplied `submissionId` when loading an incomplete submission, with no session binding, ownership check, or edit token validation.
An unauthenticated attacker could enume
ghsa
CVE-2025-32426P4MEDIUMCVSS 5.4fixed in 2.1.442025-04-11
CVE-2025-32426 [MEDIUM] CWE-79 CVE-2025-32426: Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject m
Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. T
ghsanvdosv
CVE-2025-32427P4MEDIUMCVSS 5.4fixed in 2.1.442025-04-11
CVE-2025-32427 [MEDIUM] CWE-79 CVE-2025-32427: Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, i
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't correctly escaped when viewing a preview of what was to be imported. As imports are undertaking primarily by users who have themselves exported the form from one environment to
ghsanvdosv
CVE-2024-35191P4MEDIUMCVSS 4.4fixed in 2.0.44≥ 2.1.0, < 2.1.6+1 more2024-05-20
CVE-2024-35191 [MEDIUM] CWE-1336 CVE-2024-35191: Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's setti
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.
ghsanvdosv