CVE-2025-32426: Formie has a XSS vulnerability for email notification content for preview
Impact It is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email).
This would require access to the form's email notification settings.
Patches This has been fixed in Formie 2.1.44. Users should ensure they are running at least this version.
Other sources
Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32426?
CVE-2025-32426 has been classified as a moderate severity vulnerability due to the potential for code injection into email notifications.
How do I fix CVE-2025-32426?
To fix CVE-2025-32426, update the Formie plugin to version 2.1.44 or higher.
What versions are affected by CVE-2025-32426?
CVE-2025-32426 affects all versions of the Formie Craft CMS plugin prior to version 2.1.44.
What impact does CVE-2025-32426 have on users?
CVE-2025-32426 can allow attackers to inject malicious code into email notifications viewed in the preview.
Is there an exploit available for CVE-2025-32426?
While no specific exploit has been publicly documented, the vulnerability itself allows for code injection, making it potentially exploitable.