Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.
History

Wed, 17 Sep 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Verbb
Verbb formie
CPEs cpe:2.3:a:verbb:formie:*:*:*:*:*:*:*:*
Vendors & Products Verbb
Verbb formie

Fri, 11 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
Description Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.
Title Formie has a XSS vulnerability for email notification content for preview
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-11T13:42:21.972Z

Updated: 2025-04-11T14:16:53.734Z

Reserved: 2025-04-08T10:54:58.367Z

Link: CVE-2025-32426

cve-icon Vulnrichment

Updated: 2025-04-11T14:16:13.350Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-11T14:15:25.320

Modified: 2025-09-17T18:35:09.917

Link: CVE-2025-32426

cve-icon Redhat

No data.