Unauthenticated Page-Content Overwrite in Grav Form Plugin
CVE-2026-42845
7.7HIGH
What is CVE-2026-42845?
The Grav form plugin allows unauthorized users to upload files, leading to potential overwriting of page content. Prior to version 9.1.0, a permissive upload policy could enable an attacker to upload files with dangerous extensions, thereby compromising the site's integrity. Fortunately, version 9.1.0 addresses this issue by stripping path components from uploaded filename requests and blocking specific file extensions, greatly enhancing the security of form uploads. Website administrators are strongly encouraged to update to the latest version to mitigate these risks.
Affected Version(s)
grav-plugin-form < 9.1.0
