Stored Cross-Site Scripting in Grav Form Plugin by Grav
CVE-2026-72821
5.1MEDIUM
What is CVE-2026-72821?
The Grav Form plugin, specifically versions prior to 9.1.15, is susceptible to a stored cross-site scripting vulnerability. This issue arises from how radio and toggle field option labels are rendered using the Twig |raw filter. Attackers who possess form authoring permissions can inject malicious HTML and script payloads into these option labels. Once injected, the payloads execute within the browsers of users, including both visitors and administrators who are viewing the form, potentially leading to unauthorized actions and data exposure.
Affected Version(s)
grav 0 < 9.1.15
grav 9.1.15
