Medium severity5.4NVD Advisory· Published Aug 18, 2026· Updated Sep 8, 2026
CVE-2026-75107
CVE-2026-75107
Description
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw filters and unquoted attributes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <9.1.19
Patches
Vulnerability mechanics
References
2News mentions
2- Grav CMS: 14 Vulnerabilities Including Critical Privilege Escalation Disclosed TogetherVypr Intelligence · Aug 19, 2026
- Grav CMS: Six Vulnerabilities Including File Write and XSS Disclosed TogetherVypr Intelligence · Aug 18, 2026