CVE-2026-72821 MEDIUM

CVE-2026-72821: Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle

Vendor Getgrav
Product grav
Weakness CWE-79 · XSS
Published August 14, 2026
Last update August 14, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.

Key dates

02Disclosure timeline

August 14, 2026 CVE published

Related vulnerabilities

04Related CVE