solspace/craft-freeform
The most flexible and user-friendly form building plugin for Craft CMS!
Activity
- Latest release
- 4d ago
- Total releases
- 556
- Cadence
- ~3 days
- Last 12 months
- 73
Reach
- Stars
- 54
Details
- First release
- Jan 24, 2018
| Version | Released | |
|---|---|---|
6.0.0-beta.4
pre
|
6.0.0-beta.4
pre
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
5.15.22
patch
|
5.15.22
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
5.15.21
patch
| ||
6.0.0-beta.3
pre
|
6.0.0-beta.3
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
5.15.20
patch
|
5.15.20
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
5.15.19
patch
| ||
5.15.18
patch
| ||
5.15.17
patch
| ||
6.0.0-beta.2
pre
| ||
5.15.16
patch
| ||
6.0.0-beta.1
pre
| ||
5.15.15
patch
| ||
5.15.14
patch
| ||
5.15.13
patch
| ||
5.15.12
patch
| ||
5.15.11
patch
| ||
5.15.10
patch
| ||
5.15.9
patch
| ||
5.15.8
patch
| ||
5.15.7
patch
| ||
5.15.6.1
patch
| ||
5.15.6
patch
| ||
5.15.5
patch
| ||
5.15.4
patch
| ||
5.15.3
patch
| ||
5.15.2
patch
| ||
5.15.1
patch
| ||
5.15.0
minor
| ||
5.14.24
patch
| ||
5.14.23
patch
| ||
5.14.22
patch
| ||
5.14.21
patch
| ||
5.14.20
patch
| ||
5.14.19
patch
| ||
5.14.18
patch
| ||
5.14.17
patch
| ||
5.14.16
patch
| ||
5.14.15
patch
| ||
5.14.14
patch
| ||
5.14.13
patch
| ||
5.14.12
patch
| ||
5.14.11
patch
| ||
4.1.31
patch
|
4.1.31
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
5.14.10
patch
| ||
5.14.9
patch
|
5.14.9
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
5.14.8
patch
| ||
5.14.7
patch
| ||
5.14.6
patch
1 CVE
CVE-2026-26188
GHSA-jp3q-wwp3-pwv9
Jan 22, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
Network
Low
None
Summary
An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with Affected Product
Details
PoCs
Impact Arbitrary JS in admin CP; session/CSRF token theft; potential full admin takeover via DOM-driven actions. Remediation
Workarounds
Credits
Affected versions
5.0.0
5.0.1
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.14.1
5.0.15
5.0.16
5.0.2
5.0.3
+ 158 more Show less
5.0.4
5.0.5
5.0.6
5.0.6.1
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.13
5.1.13.1
5.1.14
5.1.15
5.1.16
5.1.16.1
5.1.17
5.1.18
5.1.18.1
5.1.19
5.1.19.1
5.1.2
5.1.3
5.1.4
5.1.5
5.1.5.1
5.1.6
5.1.7
5.1.8
5.1.9
5.10.0
5.10.1
5.10.10
5.10.11
5.10.12
5.10.13
5.10.14
5.10.15
5.10.15.1
5.10.16
5.10.16.1
5.10.17
5.10.17.1
5.10.2
5.10.3
5.10.4
5.10.5
5.10.6
5.10.7
5.10.8
5.10.9
5.11.0
5.11.1
5.11.10
5.11.11
5.11.12
5.11.13
5.11.14
5.11.16
5.11.17
5.11.2
5.11.3
5.11.4
5.11.5
5.11.6
5.11.7
5.11.8
5.11.9
5.12.0
5.12.1
5.12.2
5.12.3
5.12.4
5.13.0
5.13.1
5.13.2
5.13.3
5.13.4
5.13.5
5.13.6
5.13.7
5.13.8
5.14.0
5.14.1
5.14.2
5.14.3
5.14.4
5.14.5
5.14.6
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.3.3.1
5.3.4
5.3.5
5.4.0
5.4.1
5.4.2
5.5.0
5.5.1
5.5.10
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.5.9
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.7.0
5.7.0.1
5.7.1
5.7.2
5.7.3
5.7.4
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5
5.8.6
5.8.7
5.9.0
5.9.1
5.9.1.1
5.9.1.2
5.9.10
5.9.11
5.9.12
5.9.13
5.9.14
5.9.15
5.9.16
5.9.16.1
5.9.2
5.9.3
5.9.4
5.9.5
5.9.6
5.9.7
5.9.8
5.9.9
Fixed in
5.14.7
References
Updated Feb 13, 2026 · Source: OSV.dev | ||
4.1.30
patch
| ||
5.14.5
patch
1 CVE
CVE-2026-26188
GHSA-jp3q-wwp3-pwv9
Jan 22, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
Network
Low
None
Summary
An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with Affected Product
Details
PoCs
Impact Arbitrary JS in admin CP; session/CSRF token theft; potential full admin takeover via DOM-driven actions. Remediation
Workarounds
Credits
Affected versions
5.0.0
5.0.1
5.0.10
5.0.11
5.0.12
5.0.13
5.0.14
5.0.14.1
5.0.15
5.0.16
5.0.2
5.0.3
+ 158 more Show less
5.0.4
5.0.5
5.0.6
5.0.6.1
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.1.10
5.1.11
5.1.12
5.1.13
5.1.13.1
5.1.14
5.1.15
5.1.16
5.1.16.1
5.1.17
5.1.18
5.1.18.1
5.1.19
5.1.19.1
5.1.2
5.1.3
5.1.4
5.1.5
5.1.5.1
5.1.6
5.1.7
5.1.8
5.1.9
5.10.0
5.10.1
5.10.10
5.10.11
5.10.12
5.10.13
5.10.14
5.10.15
5.10.15.1
5.10.16
5.10.16.1
5.10.17
5.10.17.1
5.10.2
5.10.3
5.10.4
5.10.5
5.10.6
5.10.7
5.10.8
5.10.9
5.11.0
5.11.1
5.11.10
5.11.11
5.11.12
5.11.13
5.11.14
5.11.16
5.11.17
5.11.2
5.11.3
5.11.4
5.11.5
5.11.6
5.11.7
5.11.8
5.11.9
5.12.0
5.12.1
5.12.2
5.12.3
5.12.4
5.13.0
5.13.1
5.13.2
5.13.3
5.13.4
5.13.5
5.13.6
5.13.7
5.13.8
5.14.0
5.14.1
5.14.2
5.14.3
5.14.4
5.14.5
5.14.6
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
5.3.3.1
5.3.4
5.3.5
5.4.0
5.4.1
5.4.2
5.5.0
5.5.1
5.5.10
5.5.2
5.5.3
5.5.4
5.5.5
5.5.6
5.5.7
5.5.8
5.5.9
5.6.0
5.6.1
5.6.2
5.6.3
5.6.4
5.6.5
5.6.6
5.6.7
5.6.8
5.7.0
5.7.0.1
5.7.1
5.7.2
5.7.3
5.7.4
5.8.0
5.8.1
5.8.2
5.8.3
5.8.4
5.8.5
5.8.6
5.8.7
5.9.0
5.9.1
5.9.1.1
5.9.1.2
5.9.10
5.9.11
5.9.12
5.9.13
5.9.14
5.9.15
5.9.16
5.9.16.1
5.9.2
5.9.3
5.9.4
5.9.5
5.9.6
5.9.7
5.9.8
5.9.9
Fixed in
5.14.7
References
Updated Feb 13, 2026 · Source: OSV.dev |
5.14.5
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|