PT-2026-4737 · Packagist · Solspace/Craft-Freeform
Published
2026-01-15
·
Updated
2026-01-15
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Summary
The latest versions of both 4.x and 5.x are using Axios versions < 1.7.5 and as such are subject to known vulnerabilities as per: https://security.snyk.io/package/npm/axios
Details
We've had this flagged up in a pen test, which indicates the issue stems from this script: /freeform/plugin.js. I couldn't see any reference to vulnerable axios versions in your package.json files, but noticed some precompiled files in packages/plugin so I'm assuming those are where the issue lies.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solspace/Craft-Freeform