The most user-friendly forms plugin for Craft.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10244 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. verbb/formie is vulnerable to Path Traversal in versions 0.0.1 - 2.2.11 and 3.0.0 - 3.1.12. | 0.0.1 - 2.2.113.0.0 - 3.1.12 | High |
AIKIDO-2025-10234 verbb/formie is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.1.43 and 3.0.0 - 3.0.22. | 2.0.0 - 2.1.433.0.0 - 3.0.22 | High |
CVE-2025-32427 verbb/formie is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.43. | 0.0.0 - 2.1.43 | Medium |
AIKIDO-2024-10186 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. verbb/formie is vulnerable to Cross-site Scripting (XSS) in versions 1.2.0 - 2.1.20. | 1.2.0 - 2.1.20 | Low |
CVE-2024-35191 verbb/formie is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 2.1.6. | 0.0.0 - 2.1.6 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
verbb/auth Version ^2.0.33 | — | — |
verbb/base Version ^3.0.8 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
dompdf/dompdf Version ^1.0.2 || ^2.0.3 | — | — |
fakerphp/faker Version ^1.9.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant