Exploitable Server-Side Template Evaluation in Craft CMS Plugin by Verbb
CVE-2026-52889

9.8CRITICAL

Key Information:

Vendor

Verbb

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-52889?

The Formie plugin for Craft CMS, before version 3.1.27, is susceptible to server-side template evaluation vulnerabilities. This occurs when an unauthorized user is able to introduce Twig syntax through various request-controlled inputs, such as hidden fields in a public form. When these inputs are processed during form rendering, they are evaluated on the server side instead of being treated as plain strings. This flaw could potentially lead to the disclosure of sensitive information, unauthorized modifications to the application's state, or even remote code execution, depending on the site's configuration and available Twig functionalities. Users are advised to upgrade to Formie version 3.1.27 or later for remediation.

Affected Version(s)

formie < 3.1.27

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.