CVE-2025-32427 affects the Formie plugin for Craft CMS, specifically versions prior to 2.1.44. This vulnerability, categorized as CWE-79 (Improper Neutralization of Input During Web Page Generation), involves a reflected cross-site scripting (XSS) flaw during form import previews. An attacker could inject malicious content into the field label or handle within a JSON form export, which would then execute when a user previews the import. The vulnerability has a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction (UI:R). While it could lead to limited confidentiality and integrity impacts (C:L, I:L), the attack requires a privileged user to deliberately tamper with a JSON export. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting a low level of public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.44CPE matchmatch criteria | cpe:2.3:a:verbb:formie:*:*:*:*:*:craft_cms:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.