CVE-2025-52122: Code Injection
Published Aug 27, 2025
·Updated
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
Affected Software
3 affected componentsFixes available
CraftCMS Freeform>=5.0.0<5.10.16
composer/solspace/craft-freeform>=5.0.0<5.10.16
5.10.16
Solspace Freeform Craft Cms>=5.0.0<5.10.16
Event History
Aug 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:33 PM
Data Sourced
via GitHub·03:33 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52122?
CVE-2025-52122 is a high severity vulnerability due to its potential for arbitrary code injection.
2
How do I fix CVE-2025-52122?
To fix CVE-2025-52122, update the CraftCMS Freeform plugin to version 5.10.16 or later.
3
Who is affected by CVE-2025-52122?
All users with access to editing form submission titles in Freeform versions 5.0.0 to before 5.10.16 are affected by CVE-2025-52122.
4
What type of vulnerability is CVE-2025-52122?
CVE-2025-52122 is classified as a Server-side Template Injection (SSTI) vulnerability.
5
Can CVE-2025-52122 be exploited remotely?
Yes, CVE-2025-52122 can be exploited remotely by any user with access to the form editing functionality.