PT-2026-7943 · WordPress+1 · Freeforum+1

Prav33N-Sec

·

Published

2026-01-22

·

Updated

2026-02-13

·

CVE-2026-26188

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Solspace Freeform plugin for Craft CMS versions 5.0 through 5.14.6
Description A low-privilege authenticated user with form creation/editing permissions can inject arbitrary HTML and JavaScript code into the Craft Control Panel builder and integrations views. Form labels and integration metadata, controlled by the user, are rendered using dangerouslySetInnerHTML without proper sanitization, resulting in stored cross-site scripting (XSS). This allows for the execution of malicious scripts when any administrator views the builder or integration screens.
Recommendations Update to version 5.14.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-26188
GHSA-JP3Q-WWP3-PWV9

Affected Products

Craft Cms
Freeforum