{"id":"CVE-2026-45697","aliases":["GHSA-x7m9-mwc2-g6w2"],"url":"https://o3.security/vulnerability/CVE-2026-45697","summary":"Formie: Pre-authenticated server-side template injection in Hidden fields","details":"Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.","published":"2026-05-29T19:01:49.220Z","modified":"2026-08-12T03:51:21.489141358Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00475,"percentile":0.38938,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"verbb/formie","fixedVersion":"3.1.24"},{"ecosystem":"Packagist","name":"verbb/formie","fixedVersion":"2.2.20"}],"fix":{"url":"https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3","label":"verbb/formie@f690d56"},"references":[{"type":"WEB","url":"https://github.com/verbb/formie/releases/tag/2.2.20"},{"type":"WEB","url":"https://github.com/verbb/formie/releases/tag/3.1.24"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45697.json"},{"type":"ADVISORY","url":"https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45697"},{"type":"FIX","url":"https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.489141358Z"}}