CVE-2026-47266: Verbb Formie
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.
Affected products
- Verbb Formie: before 2.2.21 (fixed in 2.2.21); from 3.0.0-beta.1, before 3.1.26 (fixed in 3.1.26)
Published 2026-05-29. Last modified 2026-07-22.