๐Ÿ” CVE Alert

CVE-2026-73858

MEDIUM 5.3

Solspace Freeform: Limited Twig template injection via submitted field values

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in submitted field values, including value attributes, and receive evaluated PHP, operating-system, or Craft filesystem-path constants in the form response. The isolated context was not shown to expose Craft globals, environment variables, credentials, arbitrary files, or code execution, so the confirmed impact is limited server and environment information disclosure and possible rendering errors. This issue is fixed in version 5.10.14.

CWE CWE-1336
Vendor solspace
Product craft-freeform
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for solspace craft-freeform

Be the first to know when new medium vulnerabilities affecting solspace craft-freeform are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

solspace / craft-freeform
>= 5.0.0, < 5.10.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/solspace/craft-freeform/security/advisories/GHSA-gxrg-x694-283w github.com: https://github.com/solspace/craft-freeform/pull/1986 github.com: https://github.com/solspace/craft-freeform/commit/5f7555320635f1cd3b4c478aa0b58e8c3144313b github.com: https://github.com/solspace/craft-freeform/releases/tag/v5.10.14