Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9rg8-2wvr-fgjh | Formie: Missing authorization on sent notification resend modal exposes submission PII |
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Verbb
Verbb formie |
|
| Vendors & Products |
Verbb
Verbb formie |
Wed, 23 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs and read recipient headers and complete HTML email bodies containing submitted form data, even without the sent-notification viewing permission. This issue is fixed in versions 2.2.23 and 3.1.31. | |
| Title | Formie: Missing authorization on sent notification resend modal exposes submission PII | |
| Weaknesses | CWE-200 CWE-639 CWE-862 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:42:05.461Z
Reserved: 2026-08-18T21:17:32.201Z
Link: CVE-2026-76089
Updated: 2026-09-23T19:04:51.219Z
Status : Received
Published: 2026-09-23T19:19:14.720
Modified: 2026-09-23T20:17:14.777
Link: CVE-2026-76089
No data.
OpenCVE Enrichment
Updated: 2026-09-23T20:00:08Z

Github GHSA