CVE-2026-86194: Grav Form Plugin before 9.1.22 Cross-Page Form Execution

Published Sep 5, 2026
·
Updated

Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.

Affected Software

1 affected component
Grav Form Plugin<9.1.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Grav Form Plugin to a version that resolves this vulnerability.

    Fixed in 9.1.22

Event History

Sep 5, 2026
CVE Published
via MITRE·12:09 PM
Data Sourced
via MITRE·12:09 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

Sites using Grav Form Plugin versions before 9.1.22 are exposed if they have a public page that accepts POST requests and forms defined by name on login-restricted or unpublished pages.

2

What does an attacker need to exploit this issue?

An attacker only needs anonymous access to a public page and the name of a form defined on a restricted or unpublished page. They can submit a POST request to the public page using that form name.

3

What actions could be triggered without authentication?

Depending on the restricted form's configured actions, an attacker may trigger save, upload, email, or call actions.

4

How can I tell whether my site is affected?

Check whether the installed Grav Form Plugin version is earlier than 9.1.22. Also review forms on login-restricted or unpublished pages and determine whether their names can be submitted through public pages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203