CVE-2026-45697
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-94, CWE-693, CWE-1336
Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.
Affected packages
| Packagist | verbb/formie | 0 → 2.2.20 |
| Packagist | verbb/formie | 3.0.0-beta.1 → 3.1.24 |
References
Status: profiled · ingested 2026-07-22T12:00:18.000Z