CVE-2026-45697Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-693CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-29); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-18: 1Mentions · 2026-05-29: 2Mentions · 2026-06-19: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-29: 2Technical Details · 2026-06-19: 105-1805-2906-19
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-05-292
Disclosure2
2026-06-191
General1
Full discourse4 posts
  • IntegSec@integ_sec
    General

    CVE-2026-45697: Formie Craft CMS Plugin Remote Code Execution - What It Means for Your Business and How to Respond https://hubs.li/Q04m0YGD0

    Post summary

    The information provided only names a remote code execution vulnerability in the Formie Craft CMS Plugin, without details on PoC, patches, or active exploitation.

    0000029
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45697 Unauthenticated Twig Injection in Formie Craft CMS Plugin... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45697 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE‑2026‑45697 as an unauthenticated Twig injection in a Craft CMS plugin, providing limited technical detail but no PoC, exploit, or patch information.

    0000099
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45697 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value … https://www.cve.org/CVERecord?id=CVE-2026-45697

    Post summary

    The snippet announces CVE‑2026‑45697, noting that unauthenticated users can submit crafted values into hidden fields in the Formie plugin before versions 2.2.20 and 3.1.24, and references those versions as fixes.

    00000203
    57.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Craft CMS (Formie Plugin), Twig Injection via Hidden Field, #CVE-2026-45697 (Critical) https://dailycve.com/craft-cms-formie-plugin-twig-injection-via-hidden-field-cve-2026-45697-critical/

    Post summary

    A new critical Twig injection vulnerability (CVE‑2026‑45697) has been disclosed for the Formie Plugin in Craft CMS, with no evidence of active exploitation or mitigations noted.

    0000098
    206 followersView on X

Explore more