PT-2026-81314 · Undefined · Undefined

CVE-2026-73858

·

Published

2026-08-25

·

Updated

2026-08-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
During a pentest engagement, I discovered a Server-Side Template Injection (SSTI) vulnerability in the Freeform plugin, used by Craft CMS. I disclosed the vulnerability to the vendor (Solspace) through a responsible disclosure process, which resulted in CVE-2026-73858 being assigned. 🔗 Advisory: https://t.co/2j1SLH1iwF #CVE #Pentest #SSTI #CraftCMS #SecurityResearch #InfoSec
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-73858

Affected Products

Undefined