{"id":"CVE-2026-26188","aliases":["GHSA-jp3q-wwp3-pwv9"],"url":"https://o3.security/vulnerability/CVE-2026-26188","summary":"Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft Plugin CP UI (builder/integrations)","details":"Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with dangerouslySetInnerHTML without sanitization, leading to stored XSS that executes when any admin views the builder/integration screens. This vulnerability is fixed in 5.14.7.","published":"2026-02-12T22:55:19.859Z","modified":"2026-08-12T03:51:21.102657301Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"solspace/craft-freeform","fixedVersion":"5.14.7"}],"fix":{"url":"https://github.com/solspace/craft-freeform/commit/b9adad6cdf1eba5400aae8b1ae39bd7d4d33af5e","label":"solspace/craft-freeform@b9adad6"},"references":[{"type":"WEB","url":"https://github.com/solspace/craft-freeform/releases/tag/v5.14.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26188.json"},{"type":"ADVISORY","url":"https://github.com/solspace/craft-freeform/security/advisories/GHSA-jp3q-wwp3-pwv9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26188"},{"type":"FIX","url":"https://github.com/solspace/craft-freeform/commit/b9adad6cdf1eba5400aae8b1ae39bd7d4d33af5e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.102657301Z"}}