PatchSiren cyber security CVE debrief
CVE-2026-45697 verbb CVE debrief
Formie, a Craft CMS plugin for form creation, contains a critical server-side template injection (SSTI) vulnerability in versions prior to 2.2.20 and 3.1.24. The flaw exists in Hidden fields configured with Default value → Custom, where unauthenticated user input is evaluated as Twig template code during form submission handling. This allows remote attackers to execute arbitrary code within the Craft CMS environment, potentially leading to complete site compromise. The vulnerability is exploitable without authentication and requires no user interaction, making it suitable for automated attacks. The CVSS 3.1 score of 9.8 reflects network attack vector, low attack complexity, no privileges required, no user interaction, and high impact across confidentiality, integrity, and availability. The vendor (Verbb) has released patched versions and published a security advisory. Organizations using affected Formie versions should prioritize upgrading to 2.2.20 or 3.1.24 immediately, as no workarounds are documented.
- Vendor
- verbb
- Product
- formie
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-07-22
Who should care
Organizations running Craft CMS with the Formie plugin installed, particularly those exposing forms with Hidden fields to unauthenticated users. Web application security teams managing PHP-based CMS platforms. Developers and site administrators using Formie for form management who have not yet applied the May 2026 security updates.
Technical summary
The Formie plugin for Craft CMS fails to sanitize user input in Hidden fields with custom default values, passing submitted data directly to Twig template evaluation during form processing. This server-side template injection vulnerability allows unauthenticated attackers to execute arbitrary Twig code, which in Craft CMS context enables PHP code execution and full application compromise. The vulnerability affects both major version branches (2.x and 3.x) and was introduced by insufficient input validation on the Default value → Custom field configuration option.
Defensive priority
critical
Recommended defensive actions
- Upgrade Formie to version 2.2.20 (for Craft 4.x) or 3.1.24 (for Craft 5.x) immediately
- Review form configurations for any Hidden fields using Default value → Custom and verify no unauthorized template modifications
- Audit Craft CMS logs for suspicious Twig template execution or unexpected form submissions
- If immediate patching is not possible, consider disabling form submissions or restricting access to Formie-managed forms
- Review and rotate any potentially exposed credentials or API keys accessible to the Craft CMS application
Evidence notes
Vulnerability description and affected versions derived from CVE record and GitHub Security Advisory. CVSS vector and score from NVD source data. Patch commits and release tags confirmed via GitHub references. CWE classifications (CWE-94, CWE-693, CWE-1336) from official source. No KEV listing present.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45697 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45697
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45697 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45697
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/verbb/formie/commit/f690d5623163ce2a95da305238d6367575486ee3
-
Source reference
Unverified legacy reference
URL: https://github.com/verbb/formie/releases/tag/2.2.20
-
Source reference
Unverified legacy reference
URL: https://github.com/verbb/formie/releases/tag/3.1.24
-
Source reference
Unverified legacy reference
URL: https://github.com/verbb/formie/security/advisories/GHSA-x7m9-mwc2-g6w2
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.