Skip to content

XSS vulnerability for email notification content for preview

Moderate
engram-design published GHSA-2xm2-23ff-p8ww Apr 11, 2025

Package

composer verbb/formie (Composer)

Affected versions

<= 2.1.43

Patched versions

2.1.44

Description

Impact

It is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email).

This would require access to the form's email notification settings.

Patches

This has been fixed in Formie 2.1.44. Users should ensure they are running at least this version.

Severity

Moderate

CVE ID

CVE-2025-32426

Weaknesses

No CWEs