CVE-2025-52122

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
References
Link Resource
https://github.com/TimTrademark/CVE-2025-52122 Exploit Third Party Advisory
https://github.com/TimTrademark/CVE-CraftCMS-Freeform Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:solspace:freeform:*:*:*:*:*:craft_cms:*:*

History

09 Sep 2025, 18:53

Type Values Removed Values Added
CPE cpe:2.3:a:solspace:freeform:*:*:*:*:*:craft_cms:*:*
First Time Solspace
Solspace freeform
References () https://github.com/TimTrademark/CVE-2025-52122 - () https://github.com/TimTrademark/CVE-2025-52122 - Exploit, Third Party Advisory
References () https://github.com/TimTrademark/CVE-CraftCMS-Freeform - () https://github.com/TimTrademark/CVE-CraftCMS-Freeform - Exploit, Third Party Advisory

29 Aug 2025, 16:24

Type Values Removed Values Added
Summary
  • (es) Freeform 5.0.0 a anterior a 5.10.16, un complemento para CraftCMS, contiene una vulnerabilidad de Server-side template injection (SSTI), que resulta en la inyección de código arbitrario para todos los usuarios que tienen acceso para editar un formulario (título de envío).

27 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-27 15:15

Updated : 2025-09-09 18:53


NVD link : CVE-2025-52122

Mitre link : CVE-2025-52122

CVE.ORG link : CVE-2025-52122


JSON object : View

Products Affected

solspace

  • freeform
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine