PT-2026-4737 · Packagist · Solspace/Craft-Freeform

Published

2026-01-15

·

Updated

2026-01-15

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.

Summary

The latest versions of both 4.x and 5.x are using Axios versions < 1.7.5 and as such are subject to known vulnerabilities as per: https://security.snyk.io/package/npm/axios

Details

We've had this flagged up in a pen test, which indicates the issue stems from this script: /freeform/plugin.js. I couldn't see any reference to vulnerable axios versions in your package.json files, but noticed some precompiled files in packages/plugin so I'm assuming those are where the issue lies.

Related Identifiers

GHSA-RWR8-XRPW-9QF5

Affected Products

Solspace/Craft-Freeform