Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9rg8-2wvr-fgjh | Formie: Missing authorization on sent notification resend modal exposes submission PII |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Verbb
Verbb formie |
|
| Vendors & Products |
Verbb
Verbb formie |
Wed, 23 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31. | |
| Title | Formie: Missing authorization on sent notification resend modal exposes submission PII | |
| Weaknesses | CWE-200 CWE-639 CWE-862 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:42:05.461Z
Reserved: 2026-08-18T21:17:32.201Z
Link: CVE-2026-76089
Updated: 2026-09-23T19:04:51.219Z
Status : Received
Published: 2026-09-23T19:19:14.720
Modified: 2026-09-23T20:17:14.777
Link: CVE-2026-76089
No data.
OpenCVE Enrichment
Updated: 2026-09-23T20:00:08Z
Github GHSA