Vulnerability Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3
- https://github.com/verbb/formie/releases/tag/2.2.20
- https://github.com/verbb/formie/releases/tag/3.1.24
- https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2
FAQ
What is CVE-2026-45697?
CVE-2026-45697 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as T...
How severe is CVE-2026-45697?
CVE-2026-45697 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45697?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.