VYPR

Form plugin

by Grav CMS

CVEs (6)

  • CVE-2026-86194MedSep 5, 2026
    risk 0.45cvss epss 0.00

    Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name…

  • CVE-2026-69087MedAug 3, 2026
    risk 0.42cvss 6.5epss 0.00

    The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When…

  • CVE-2026-75107MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all…

  • CVE-2026-72821MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in…

  • CVE-2026-85602MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3…

  • CVE-2026-61873HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.00

    Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path…