GHSA-9hp3-f5g8-rccg

Suggest an improvement
Source
https://github.com/advisories/GHSA-9hp3-f5g8-rccg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-9hp3-f5g8-rccg/GHSA-9hp3-f5g8-rccg.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9hp3-f5g8-rccg
Aliases
  • CVE-2025-52122
Published
2025-08-27T15:33:15Z
Modified
2025-08-27T18:27:27.449478Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability
Details

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

Database specific
{
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2025-08-27T18:10:27Z",
    "nvd_published_at": "2025-08-27T15:15:39Z",
    "cwe_ids": [
        "CWE-94"
    ]
}
References

Affected packages

Packagist / solspace/craft-freeform

Package

Name
solspace/craft-freeform
Purl
pkg:composer/solspace/craft-freeform

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.10.16

Affected versions

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.6.1
5.0.7
5.0.8
5.0.9
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.14.1
5.0.15
5.0.16
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.1.5
5.1.5.1
5.1.6
5.1.7
5.1.8
5.1.9
5.1.10
5.1.11
5.1.12
5.1.13
5.1.13.1
5.1.14
5.1.15
5.1.16
5.1.16.1
5.1.17
5.1.18
5.1.18.1
5.1.19
5.1.19.1
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.3.3.1
5.3.4
5.3.5
5.4.0
5.4.1
5.4.2
5.5.0
5.5.1
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.5.9
5.5.10
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.7.0
5.7.0.1
5.7.1
5.7.2
5.7.3
5.7.4
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5
5.8.6
5.8.7
5.9.0
5.9.1
5.9.1.1
5.9.1.2
5.9.2
5.9.3
5.9.4
5.9.5
5.9.6
5.9.7
5.9.8
5.9.9
5.9.10
5.9.11
5.9.12
5.9.13
5.9.14
5.9.15
5.9.16
5.9.16.1
5.10.0
5.10.1
5.10.2
5.10.3
5.10.4
5.10.5
5.10.6
5.10.7
5.10.8
5.10.9
5.10.10
5.10.11
5.10.12
5.10.13
5.10.14
5.10.15
5.10.15.1