Stored XSS Vulnerability in Grav Form Plugin by Grav
CVE-2026-75107
5.1MEDIUM
What is CVE-2026-75107?
The Grav Form Plugin, prior to version 9.1.19, is susceptible to a stored Cross-Site Scripting vulnerability. This occurs due to improper escaping of field-definition properties such as prepend, append, spacer text, section text, and select option labels in form templates. Malicious users with form authoring privileges can exploit this vulnerability to inject arbitrary HTML and JavaScript into form templates, which then executes in the browsers of all visitors interacting with the affected forms. This can lead to theft of sensitive information or other malicious actions.
Affected Version(s)
grav 0 < 9.1.19
grav 9.1.19
