VendorsSolspacefreeformany version
Vulnerabilities

Solspace Freeform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-52122
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
Published 2025-08-27 · Analyzed
9.8EPSS 0.006
CVE-2026-26188
Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft Plugin CP UI (builder/integrations)
Published 2026-02-12 · Analyzed
5.4EPSS 0.003