Security Advisory

CVE-2026-72821

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-14 11:35:30
Last updated 2026-08-14 11:35:30
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.