Stored Cross-Site Scripting in Grav Form Plugin by Grav
CVE-2026-72821

5.1MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-72821?

The Grav Form plugin, specifically versions prior to 9.1.15, is susceptible to a stored cross-site scripting vulnerability. This issue arises from how radio and toggle field option labels are rendered using the Twig |raw filter. Attackers who possess form authoring permissions can inject malicious HTML and script payloads into these option labels. Once injected, the payloads execute within the browsers of users, including both visitors and administrators who are viewing the form, potentially leading to unauthorized actions and data exposure.

Affected Version(s)

grav 0 < 9.1.15

grav 9.1.15

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HDWSec
.