Skip to main content

Vendor/product archive

solspace / freeform CVEs

Beta · best-effort

2 CVEs tagged to solspace / freeform1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-26188

Published Feb 12, 2026

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS in…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-52122

Published Aug 27, 2025

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1