CVE-2026-72821: Getgrav Grav
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.
Affected products
- Getgrav Grav: before 9.1.15 (fixed in 9.1.15)
Published 2026-08-14. Last modified 2026-08-31.