Vulnerability DatabaseGHSA-jp3q-wwp3-pwv9

GHSA-jp3q-wwp3-pwv9: 
PHP vulnerability analysis and mitigation

Summary An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with dangerouslySetInnerHTML without sanitization, leading to stored XSS that executes when any admin views the builder/integration screens. Affected Product

  • Ecosystem: Packagist (Craft CMS plugin)
  • Package: solspace/craft-freeform
  • Version: <= 5.14.6 (latest observed). Likely all 5.x until patched. Details
  • Root cause: Multiple user-controlled strings (field labels, section labels, integration icons, short names, WYSIWYG previews) are injected into React components using dangerouslySetInnerHTML without sanitization.
  • Evidence: dangerouslySetInnerHTML on user-controlled properties in bundled CP JS at packages/plugin/src/Resources/js/client/client.js. PoCs
  • Label-based XSS:
    1. In Craft CP, create/edit a Freeform field and set its label to <img src=x onerror="alert('xss-label')">.
    2. Open the form builder view containing the field.
    3. Alert executes (stored XSS).
  • Integration icon SVG:
    1. Set an integration "icon SVG" to <svg><script>alert('xss-icon')</script></svg>.
    2. Open the integrations CP view.
    3. Script executes. Impact Arbitrary JS in admin CP; session/CSRF token theft; potential full admin takeover via DOM-driven actions. Remediation
  • Sanitize/HTML-encode all user-controlled strings before passing to dangerouslySetInnerHTML, or avoid it for labels/titles/icons.
  • Server-side: strip/escape disallowed tags on save for fields, integration metadata, WYSIWYG content.
  • Add regression tests with <img onerror> payloads to ensure no execution in builder/integration views. Workarounds
  • Restrict form-edit permissions to trusted admins only until patched.
  • Consider CSP that disallows inline scripts (defense-in-depth only). Credits
  • Discovered by https://www.linkedin.com/in/praveenkavinda/ | Prav33N-Sec.

Source: NVD

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management