We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.
Reserved 2024-05-10 | Published 2024-05-20 | Updated 2024-08-02 | Assigner GitHub_MCWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
github.com/...formie/security/advisories/GHSA-v45m-hxqp-fwf5
github.com/...ommit/90296edf7e707f117e760aa57e70dbd43a854420
Support options