Known Vulnerabilities for Grav-plugin-form by Getgrav
Listed below are 10 of the newest known vulnerabilities associated with "Grav-plugin-form" by "Getgrav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100673 json | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100668 json | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on t... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100667 json | grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to ... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-92916 json | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugg... | Not Provided | 2026-09-17 | 2026-09-30 |
| CVE-2026-86194 json | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymo... | Not Provided | 2026-09-05 | 2026-09-18 |
| CVE-2026-85604 json | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The ... | Not Provided | 2026-09-04 | 2026-09-08 |
| CVE-2026-85602 json | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based ... | Not Provided | 2026-09-04 | 2026-09-05 |
| CVE-2026-75574 json | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsa... | Not Provided | 2026-08-25 | 2026-08-27 |
| CVE-2026-75107 json | Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section te... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-72821 json | Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option ... | Not Provided | 2026-08-14 | 2026-08-18 |