top of page
perceptive_background_267k.jpg

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default …

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 21:09:42

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

The Formie plugin for Craft CMS contains a critical vulnerability where unauthenticated users can inject malicious Twig code through hidden form fields with custom default values. This server-side template injection vulnerability affects versions prior to 2.2.20 and 3.1.24 and can lead to complete compromise of the Craft CMS site. The vulnerability occurs during form submission handling when crafted values in hidden fields are evaluated as Twig templates. The impact depends on the specific template and sandbox configuration but can result in serious security compromise. Patches are available in versions 2.2.20 and 3.1.24.

Technical details

Mitigation steps:

Affected products:

Formie
Craft CMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page