CVE-2024-35191

MEDIUM

Formie <2.1.6 - Code Injection

Title source: llm
STIX 2.1

Description

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text. This has been fixed in Formie 2.1.6.

Scores

CVSS v3 4.4
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1336
Status published
Products (2)
verbb/formie < 2.0.44
verbb/formie 0 - 2.1.6Packagist
Published May 20, 2024
Tracked Since Feb 18, 2026