Stored XSS Vulnerability in Grav Form Plugin by Grav
CVE-2026-75107

5.1MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75107?

The Grav Form Plugin, prior to version 9.1.19, is susceptible to a stored Cross-Site Scripting vulnerability. This occurs due to improper escaping of field-definition properties such as prepend, append, spacer text, section text, and select option labels in form templates. Malicious users with form authoring privileges can exploit this vulnerability to inject arbitrary HTML and JavaScript into form templates, which then executes in the browsers of all visitors interacting with the affected forms. This can lead to theft of sensitive information or other malicious actions.

Affected Version(s)

grav 0 < 9.1.19

grav 9.1.19

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
.