Formcraft3 before version 3.8.2 does not validate the URL parameter in the formcraft3_get AJAX action, leading to server-side request forgery issues exploitable by unauthenticated users.
View the template here CVE-2022-0591.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-0591