solspace/craft-freeform vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26188Lowsolspace/craft-freeform: Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issueGHSA-RWR8-XRPW-9QF5Lowsolspace/craft-freeform: solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled AssetsGHSA-44JG-MV3H-WJ6GLowsolspace/craft-freeform: solspace/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling DataGHSA-58Q2-9X27-H2JMLowsolspace/craft-freeform: solspace/craft-freeform Has a DoS VulnerabilityCVE-2025-52122Criticalsolspace/craft-freeform: The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability

Stop the waste.
Protect your environment with Kodem.