CVE-2025-52122

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
References
Link Resource
https://github.com/TimTrademark/CVE-2025-52122 Exploit Third Party Advisory
https://github.com/TimTrademark/CVE-CraftCMS-Freeform Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:solspace:freeform:*:*:*:*:*:craft_cms:*:*

History

No history.

Information

Published : 2025-08-27 15:15

Updated : 2025-09-09 18:53


NVD link : CVE-2025-52122

Mitre link : CVE-2025-52122

CVE.ORG link : CVE-2025-52122


JSON object : View

Products Affected

solspace

  • freeform
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine