CVE-2026-52889Critical· 9.8▾ MidnightFormie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Valu…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.7%
Last analysed / modified upstream
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when a public form contains an affected Hidden field. Hidden::getFrontEndInputOptions() then assigns the value to defaultValue and calls renderString, causing server-side template evaluation rather than treating the request data as a plain string. Depending on the Craft site configuration and available Twig capabilities, exploitation can disclose sensitive information, modify application state, or achieve remote code execution. This issue is fixed in version 3.1.27.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
verbb/formie < 3.1.27Patched in:
verbb/formie 3.1.27Connected by shared product, vendor, weakness, or advisory.
GHSA-cvpc-hccg-wmw4Medium· 6.3Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
CVE-2026-61453MediumGrav: XSS Blueprint Validation Bypass via Twig String Concatenation
CVE-2026-54718High· 7.2Silverstripe Advanced Workflow is a highly configurable step-based workflow module
CVE-2026-59989CriticalPhalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
CVE-2026-52762High· 7.1YesWiki is a wiki system written in PHP
CVE-2026-9558Critical· 9.9Mautic has Server-Side Template Injection (SSTI) in Theme Templates