CVE-2026-73858

Source
https://cve.org/CVERecord?id=CVE-2026-73858
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73858.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73858
Aliases
Published
2026-09-23T14:30:22Z
Modified
2026-09-24T03:46:01Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Solspace Freeform: Limited Twig template injection via submitted field values
Details

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in submitted field values, including value attributes, and receive evaluated PHP, operating-system, or Craft filesystem-path constants in the form response. The isolated context was not shown to expose Craft globals, environment variables, credentials, arbitrary files, or code execution, so the confirmed impact is limited server and environment information disclosure and possible rendering errors. This issue is fixed in version 5.10.14.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-1336"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73858.json"
}
References

Affected packages

Git / github.com/solspace/craft-freeform

Affected ranges

Type
GIT
Repo
https://github.com/solspace/craft-freeform
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.0.0"
        },
        {
            "fixed":  "5.10.14"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.14.1
v5.0.15
v5.0.16
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.6.1
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.1.1
v5.1.10
v5.1.11
v5.1.12
v5.1.13
v5.1.13.1
v5.1.14
v5.1.15
v5.1.16
v5.1.16.1
v5.1.17
v5.1.18
v5.1.18.1
v5.1.19
v5.1.19.1
v5.1.2
v5.1.3
v5.1.4
v5.1.5
v5.1.5.1
v5.1.6
v5.1.7
v5.1.8
v5.1.9
v5.10.0
v5.10.1
v5.10.10
v5.10.11
v5.10.12
v5.10.13
v5.10.2
v5.10.3
v5.10.4
v5.10.5
v5.10.6
v5.10.7
v5.10.8
v5.10.9
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
v5.3.3.1
v5.3.4
v5.3.5
v5.4.0
v5.4.1
v5.4.2
v5.5.0
v5.5.1
v5.5.10
v5.5.2
v5.5.3
v5.5.4
v5.5.5
v5.5.6
v5.5.7
v5.5.8
v5.5.9
v5.6.1
v5.6.2
v5.6.3
v5.6.4
v5.6.5
v5.6.6
v5.6.7
v5.6.8
v5.7.0
v5.7.0.1
v5.7.1
v5.7.2
v5.7.3
v5.7.4
v5.8.0
v5.8.1
v5.8.2
v5.8.3
v5.8.4
v5.8.5
v5.8.6
v5.8.7
v5.9.0
v5.9.1
v5.9.1.1
v5.9.1.2
v5.9.10
v5.9.11
v5.9.12
v5.9.13
v5.9.14
v5.9.15
v5.9.16
v5.9.16.1
v5.9.2
v5.9.3
v5.9.4
v5.9.5
v5.9.6
v5.9.7
v5.9.8
v5.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73858.json"