Ghostwire

CVE-2026-72821: Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field...

MEDIUM CVSS 0.0

Published: August 14, 2026 | Last Modified: August 14, 2026

Description

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References