Логотип exploitDog
bind:CVE-2025-32426
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32426

Количество 2

Количество 2

nvd логотип

CVE-2025-32426

10 месяцев назад

Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2xm2-23ff-p8ww

10 месяцев назад

Formie has XSS vulnerability for email notification content for preview

CVSS3: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32426

Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-2xm2-23ff-p8ww

Formie has XSS vulnerability for email notification content for preview

CVSS3: 4.6
0%
Низкий
10 месяцев назад

Уязвимостей на страницу