CVE-2025-32426
Formie has XSS vulnerability for email notification content for preview
4.6
MEDIUM
CVSS 3.1
EPSS 0.20%
Description
### Impact It is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. ### Patches This has been fixed in Formie 2.1.44. Users should ensure they are running at least this version.
How to fix CVE-2025-32426
To remediate CVE-2025-32426, upgrade the affected package to a fixed version below.
- —upgrade to 2.1.44 or later
Is CVE-2025-32426 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1.44
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |