The most user-friendly forms plugin for Craft.
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47266 verbb/formie is vulnerable to Authorization Bypass Through User-Controlled Key in versions 3.0.0 - 3.1.26 and 0.0.0 - 2.2.21. | 0.0.0 - 2.2.213.0.0 - 3.1.26 | |
CVE-2026-45697 verbb/formie is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 3.0.0-beta.1 - 3.1.24 and 0.0.0 - 2.2.20. | 0.0.0 - 2.2.203.0.0-beta.1 - 3.1.24 | |
AIKIDO-2026-10766 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. verbb/formie is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.3.3 - 3.1.19. | 1.3.3 - 3.1.19 | |
AIKIDO-2026-10244 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. verbb/formie is vulnerable to Path Traversal in versions 0.0.1 - 2.2.11 and 3.0.0 - 3.1.12. | 0.0.1 - 2.2.113.0.0 - 3.1.12 | |
AIKIDO-2025-10234 verbb/formie is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.1.43 and 3.0.0 - 3.0.22. | 2.0.0 - 2.1.433.0.0 - 3.0.22 |
| Dependency | Last Release | Score |
|---|---|---|
verbb/auth Version ^2.0.20 | — | — |
verbb/base Version ^3.0.11 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
dompdf/dompdf Version ^1.0.2 || ^2.0.3 | — | — |
fakerphp/faker Version ^1.9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant