Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10805 | Formie has XSS vulnerability for importing forms |
Github GHSA |
GHSA-p9hh-mh5x-wvx3 | Formie has XSS vulnerability for importing forms |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 29 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:verbb:formie:*:*:*:*:*:craft_cms:*:* |
Wed, 17 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Verbb
Verbb formie |
|
| CPEs | cpe:2.3:a:verbb:formie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Verbb
Verbb formie |
|
| Metrics |
cvssV3_1
|
Fri, 11 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't correctly escaped when viewing a preview of what was to be imported. As imports are undertaking primarily by users who have themselves exported the form from one environment to another, and would require direct manipulation of the JSON export, this is marked as moderate. This vulnerability will not occur unless someone deliberately tampers with the export. This vulnerability is fixed in 2.1.44. | |
| Title | Formie has a XSS vulnerability for importing forms | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-11T14:48:00.321Z
Reserved: 2025-04-08T10:54:58.367Z
Link: CVE-2025-32427
Updated: 2025-04-11T14:47:50.579Z
Status : Analyzed
Published: 2025-04-11T14:15:25.457
Modified: 2025-09-29T14:39:45.743
Link: CVE-2025-32427
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA