CVE-2026-72821: Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle
Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grav Form Pluginto a version that resolves this vulnerability.Fixed in 9.1.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72821?
The severity of CVE-2026-72821 is rated medium with a score of 5.4.
How do I fix CVE-2026-72821?
To mitigate CVE-2026-72821, update the Grav Form plugin to version 9.1.15 or later.
What type of vulnerability is CVE-2026-72821?
CVE-2026-72821 is a stored cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2026-72821?
Attackers with form authoring permissions can exploit CVE-2026-72821.
What components are affected by CVE-2026-72821?
CVE-2026-72821 affects versions of the Grav Form plugin prior to 9.1.15.