CVE-2026-76086High· 8.5▾ TwilightFormie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configured integration. An authenticated attacker can replace outbound host properties such as apiUrl while the server uses stored API keys or OAuth tokens, causing non-blind server-side requests to an attacker-controlled or internal host and returning the remote response. This residual flaw remained because the permission gate added in version 3.1.28 excluded the form-settings action. Sites that permit low-privileged or front-end user authentication can therefore expose integration credentials and internal network responses. This issue is fixed in versions 2.2.23 and 3.1.31.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
verbb/formie >= 3.0.0, < 3.1.31verbb/formie < 2.2.23Patched in:
verbb/formie 3.1.31verbb/formie 2.2.23Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76087High· 8.2Formie is a Craft CMS plugin for creating forms
CVE-2026-76089High· 7.7Formie is a Craft CMS plugin for creating forms
GHSA-cvpc-hccg-wmw4Medium· 6.3Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
CVE-2026-52889Critical· 9.8Formie is a Craft CMS plugin for creating forms
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0
CVE-2026-11807Critical· 9.6A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API