VYPR
Critical severity9.8NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026

CVE-2025-52122

CVE-2025-52122

Description

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
solspace/craft-freeformPackagist
>= 5.0.0, < 5.10.165.10.16

Affected products

3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.