Known Vulnerabilities for Grav-plugin-form by Getgrav
Listed below are 10 of the newest known vulnerabilities associated with "Grav-plugin-form" by "Getgrav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86194 json | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymo... | Not Provided | 2026-09-05 | 2026-09-05 |
| CVE-2026-85604 json | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The ... | Not Provided | 2026-09-04 | 2026-09-05 |
| CVE-2026-85602 json | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based ... | Not Provided | 2026-09-04 | 2026-09-05 |
| CVE-2026-75574 json | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsa... | Not Provided | 2026-08-25 | 2026-08-27 |
| CVE-2026-75107 json | Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section te... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-72821 json | Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option ... | Not Provided | 2026-08-14 | 2026-08-18 |
| CVE-2026-69087 json | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the red... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65008 json | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Commo... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-62671 json | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.rege... | Not Provided | 2026-08-19 | 2026-08-19 |