Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9rg8-2wvr-fgjh
  • Packagist/verbb/formie
Formie: Missing authorization on sent notification resend modal exposes submission PII 23 Sep
  • Fix available
  • Severity - 7.7 (High)
GHSA-584p-f93j-wpgc
  • Packagist/verbb/formie
Formie: Unauthenticated users can overwrite incomplete submissions via submit action 23 Sep
  • Fix available
  • Severity - 8.2 (High)
GHSA-v3f3-cmj4-cvj9
  • Packagist/verbb/formie
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials 23 Sep
  • Fix available
  • Severity - 8.5 (High)
GHSA-cvpc-hccg-wmw4
  • Packagist/verbb/formie
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration 17 Jul
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-565m-g33j-jq96
  • Packagist/verbb/formie
Formie Hidden field defaults vulnerable to Server-Side Template Injection 06 Jul
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-pgxq-p76c-x9cg
  • Packagist/verbb/formie
formie's unauthenticated front-end submission editing can overwrite existing submissions 29 May
  • Fix available
  • Severity - 8.7 (High)
GHSA-x7m9-mwc2-g6w2
  • Packagist/verbb/formie
Formie: Pre-authenticated server-side template injection in Hidden fields 18 May
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-2xm2-23ff-p8ww
  • Packagist/verbb/formie
Formie has XSS vulnerability for email notification content for preview 11 Apr 2025
  • Fix available
  • Severity - 4.6 (Medium)
GHSA-p9hh-mh5x-wvx3
  • Packagist/verbb/formie
Formie has XSS vulnerability for importing forms 11 Apr 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-v45m-hxqp-fwf5
  • Packagist/verbb/formie
verbb/formie Server-Side Template Injection for variable-enabled settings 20 May 2024
  • Fix available
  • Severity - 4.4 (Medium)