Unauthenticated Page-Content Overwrite in Grav Form Plugin
CVE-2026-42845

7.7HIGH

Key Information:

Vendor

Getgrav

Vendor
CVE Published:
11 May 2026

What is CVE-2026-42845?

The Grav form plugin allows unauthorized users to upload files, leading to potential overwriting of page content. Prior to version 9.1.0, a permissive upload policy could enable an attacker to upload files with dangerous extensions, thereby compromising the site's integrity. Fortunately, version 9.1.0 addresses this issue by stripping path components from uploaded filename requests and blocking specific file extensions, greatly enhancing the security of form uploads. Website administrators are strongly encouraged to update to the latest version to mitigate these risks.

Affected Version(s)

grav-plugin-form < 9.1.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.