The most user-friendly forms plugin for Craft.
89%
Total Score
100
69
80
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-723224 New verbb/formie is vulnerable to Missing Authorization in versions 1.1.0 - 2.2.25 and 3.0.0 - 3.1.33. | 1.1.0 - 2.2.253.0.0 - 3.1.33 | Medium |
AIKIDO-2026-438989 New verbb/formie is vulnerable to Server-Side Template Injection (SSTI) in versions 1.1.0 - 2.2.25 and 3.0.0 - 3.1.33. | 1.1.0 - 2.2.253.0.0 - 3.1.33 | High |
CVE-2026-52889 verbb/formie is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.0.0 - 3.1.27. | 0.0.0 - 3.1.27 | Critical |
CVE-2026-47266 verbb/formie is vulnerable to Authorization Bypass Through User-Controlled Key in versions 3.0.0 - 3.1.26 and 0.0.0 - 2.2.21. | 0.0.0 - 2.2.213.0.0 - 3.1.26 | High |
CVE-2026-45697 verbb/formie is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 3.0.0-beta.1 - 3.1.24 and 0.0.0 - 2.2.20. | 0.0.0 - 2.2.203.0.0-beta.1 - 3.1.24 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
verbb/auth Version ^2.0.20 | — | — |
verbb/base Version ^3.0.11 | — | — |
craftcms/cms Version ^5.0.0 | — | — |
verbb/tiptap Version ^1.0.0 | — | — |
dompdf/dompdf Version ^1.0.2 || ^2.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant