PT-2026-81314 · Undefined · Undefined
CVE-2026-73858
·
Published
2026-08-25
·
Updated
2026-08-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
During a pentest engagement, I discovered a Server-Side Template Injection (SSTI) vulnerability in the Freeform plugin, used by Craft CMS.
I disclosed the vulnerability to the vendor (Solspace) through a responsible disclosure process, which resulted in CVE-2026-73858 being assigned.
🔗 Advisory: https://t.co/2j1SLH1iwF #CVE #Pentest #SSTI #CraftCMS #SecurityResearch #InfoSec
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined