CVE-2026-26188
EUVD-2026-616812.02.2026, 23:16
Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with dangerouslySetInnerHTML without sanitization, leading to stored XSS that executes when any admin views the builder/integration screens. This vulnerability is fixed in 5.14.7.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| solspace | freeform | 5.0.0 ≤ 𝑥 < 5.14.7 |
𝑥
= Vulnerable software versions