Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Verbb
Verbb formie |
|
CPEs | cpe:2.3:a:verbb:formie:*:*:*:*:*:*:*:* | |
Vendors & Products |
Verbb
Verbb formie |
Fri, 11 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 11 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44. | |
Title | Formie has a XSS vulnerability for email notification content for preview | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-11T13:42:21.972Z
Updated: 2025-04-11T14:16:53.734Z
Reserved: 2025-04-08T10:54:58.367Z
Link: CVE-2025-32426

Updated: 2025-04-11T14:16:13.350Z

Status : Analyzed
Published: 2025-04-11T14:15:25.320
Modified: 2025-09-17T18:35:09.917
Link: CVE-2025-32426

No data.