PT-2026-41792 · Packagist · Verbb/Formie

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-45697

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact

  • Unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior).
  • Sites with public Formie forms that include at least one Hidden field with that configuration.
  • No CP login for the reported chain.

Patches

Workarounds

  • Temporarily remove Hidden fields from public forms or switch Hidden default away from Custom where feasible
  • Otherwise, upgrade to patched versions

Fix

Code Injection

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2026-45697
GHSA-X7M9-MWC2-G6W2

Affected Products

Verbb/Formie