
During a pentest engagement, I discovered a Server-Side Template Injection (SSTI) vulnerability in the Freeform plugin, used by Craft CMS. I disclosed the vulnerability to the vendor (Solspace) through a responsible disclosure process, which resulted in CVE-2026-73858 being assigned. 🔗 Advisory: https://github.com/solspace/craft-freeform/security/advisories/GHSA-gxrg-x694-283w #CVE #Pentest #SSTI #CraftCMS #SecurityResearch #InfoSec
Post summary
During a pentest an SSTI flaw was found in Craft CMS’s Freeform plugin; the vulnerability was responsibly disclosed to Solspace and assigned CVE‑2026‑73858, with a vendor advisory posted.
