Executive brief
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability
Affected products
- Packagist solspace/craft-freeform
Junglewise Threat Intelligence
CVE-2025-52122 · Severity: low · CVSS 3.1 · Published 2025-08-27
Technologies: solspace/craft-freeform (Packagist). Vendors: Packagist.
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability