CVE-2026-45697
Formie Craft CMS Plugin Twig Injection Vulnerability
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
A vulnerability in the Formie Craft CMS plugin allows unauthenticated users to inject and execute Twig code through crafted hidden form fields, potentially leading to severe website compromise. This issue is reachable via public web forms, posing a significant risk to site integrity and data.