Exploitable Server-Side Template Evaluation in Craft CMS Plugin by Verbb
CVE-2026-52889
9.8CRITICAL
What is CVE-2026-52889?
The Formie plugin for Craft CMS, before version 3.1.27, is susceptible to server-side template evaluation vulnerabilities. This occurs when an unauthorized user is able to introduce Twig syntax through various request-controlled inputs, such as hidden fields in a public form. When these inputs are processed during form rendering, they are evaluated on the server side instead of being treated as plain strings. This flaw could potentially lead to the disclosure of sensitive information, unauthorized modifications to the application's state, or even remote code execution, depending on the site's configuration and available Twig functionalities. Users are advised to upgrade to Formie version 3.1.27 or later for remediation.
Affected Version(s)
formie < 3.1.27
