<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:53:06.577951+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-356462</id>
    <title>EUVD-2026-356462</title>
    <updated>2026-10-06T22:53:06.632674+00:00</updated>
    <content>EUVD-2026-356462</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-356462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52889</id>
    <title>fkie_cve-2026-52889</title>
    <updated>2026-10-06T22:53:06.632711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when a public form contains an affected Hidden field. Hidden::getFrontEndInputOptions() then assigns the value to defaultValue and calls renderString, causing server-side template evaluation rather than treating the request data as a plain string. Depending on the Craft site configuration and available Twig capabilities, exploitation can disclose sensitive information, modify application state, or achieve remote code execution. This issue is fixed in version 3.1.27.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-565m-g33j-jq96</id>
    <title>GHSA-565m-g33j-jq96 — Formie Hidden field defaults vulnerable to Server-Side Template Injection</title>
    <updated>2026-10-06T22:53:06.632755+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: verbb/formie</p>
<p>## Summary
Formie Hidden fields could evaluate request-derived values as Twig during front-end form rendering.</p>
<p>When a Hidden field used a dynamic default value such as HTTP User Agent, Referer URL, Current URL, Query Parameter, or Cookie Value, the value was copied from the incoming request and later passed to Craft’s Twig rendering layer. This allowed an unauthenticated attacker to provide Twig syntax in request-controlled input and have it evaluated server-side when the form was rendered.</p>
<p>## Affected Versions
`verbb/formie` for Craft 5:
- Affected: &gt;= 3.0.0-beta.1, &lt;= 3.1.26
- Patched: 3.1.27</p>
<p>## Impact
An unauthenticated attacker could trigger server-side template evaluation by visiting a public form containing a Hidden field configured with a request-derived default value.</p>
<p>Because Craft’s normal Twig environment exposes application objects, this may lead to disclosure of sensitive information, modification of application state, or remote code execution depending on the site configuration and available Twig capabilities.</p>
<p>## Technical Details
The issue exists in the Hidden field front-end render path. Request-derived Hidden field defaults were assigned to the field’s defaultValue, then rendered via Twig in `Hidden::getFrontEndInputOptions()`.</p>
<p>The fix ensures Twig rendering is only performed for the custom default option, where the template source is admin-authored. Request-derived default options are now treated as plain strings.</p>
<p>## Patches
Update to Formie 3.1.27 or…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-565m-g33j-jq96"/>
  </entry>
</feed>
