CVE-2026-76089
Formie: Missing authorization on sent notification resend modal exposes submission PII
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31.
| CWE | CWE-200 CWE-639 CWE-862 |
| Vendor | verbb |
| Product | formie |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for verbb formie
Be the first to know when new high vulnerabilities affecting verbb formie are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
verbb / formie
< 2.2.23 >= 3.0.0, < 3.1.31
References
github.com: https://github.com/verbb/formie/security/advisories/GHSA-9rg8-2wvr-fgjh github.com: https://github.com/verbb/formie/commit/9f4e23c36b907ed7677563231eaba373fdb8b84b github.com: https://github.com/verbb/formie/commit/ff81a895fa91a2e4efb8d4714501ba2d92df0b76 github.com: https://github.com/verbb/formie/releases/tag/2.2.23 github.com: https://github.com/verbb/formie/releases/tag/3.1.31