Description
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1787 | Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6. |
Github GHSA |
GHSA-v45m-hxqp-fwf5 | verbb/formie Server-Side Template Injection for variable-enabled settings |
References
History
Mon, 29 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Verbb
Verbb formie |
|
| CPEs | cpe:2.3:a:verbb:formie:*:*:*:*:*:craft_cms:*:* | |
| Vendors & Products |
Verbb
Verbb formie |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:07:46.830Z
Reserved: 2024-05-10T14:24:24.341Z
Link: CVE-2024-35191
Updated: 2024-08-02T03:07:46.830Z
Status : Analyzed
Published: 2024-05-20T21:15:09.307
Modified: 2025-09-29T14:16:26.123
Link: CVE-2024-35191
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA