Server-Side Template Injection Affecting solspace/craft-freeform package, versions >=5.0.0-beta10, <5.10.16


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.06% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-SOLSPACECRAFTFREEFORM-12549186
  • published7 Sept 2025
  • disclosed27 Aug 2025
  • creditTimTrademark

Introduced: 27 Aug 2025

NewCVE-2025-52122  (opens in a new tab)
CWE-1336  (opens in a new tab)

How to fix?

Upgrade solspace/craft-freeform to version 5.10.16 or higher.

Overview

solspace/craft-freeform is a flexible and user-friendly form building plugin!

Affected versions of this package are vulnerable to Server-Side Template Injection via the submission's title variable. An attacker can execute arbitrary code on the server by injecting malicious templates when editing a form.

CVSS Base Scores

version 4.0
version 3.1