CVE-2024-22722: Formtools Form Tools

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

Affected products

Published 2024-04-11. Last modified 2026-06-17.