CVE-2026-26188

Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with dangerouslySetInnerHTML without sanitization, leading to stored XSS that executes when any admin views the builder/integration screens. This vulnerability is fixed in 5.14.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:solspace:freeform:*:*:*:*:*:craft_cms:*:*

History

No history.

Information

Published : 2026-02-12 23:16

Updated : 2026-06-17 10:25


NVD link : CVE-2026-26188

Mitre link : CVE-2026-26188

CVE.ORG link : CVE-2026-26188


JSON object : View

Products Affected

solspace

  • freeform
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')