What is CVE-2026-69087?
CVE-2026-69087 is an open redirect vulnerability in the Grav form plugin (getgrav/grav-plugin-form) before version 9.1.13. The flaw arises because user-supplied form data is evaluated in Twig expressions and external URLs are accepted without origin validation during the redirect process. Upgrading the plugin to version 9.1.13 or later is advised.
Azərbaycanca: CVE-2026-69087, Grav forma plaginində (getgrav/grav-plugin-form) 9.1.13 versiyasına qədər mövcud olan açıq yönləndirmə (open redirect) zəifliyidir. Zəiflik, istifadəçinin təqdim etdiyi məlumatların Twig ifadələrində işlənməsi və xarici URL-lərə mənşə doğrulaması olmadan yönləndirməyə icazə verilməsi səbəbindən yaranır. Plaginin 9.1.13 və ya daha yeni versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: getgrav
FAQ2
What plugin is affected by CVE-2026-69087 and what causes the vulnerability?
CVE-2026-69087 affects the Grav form plugin (getgrav/grav-plugin-form) in versions prior to 9.1.13. It is an open redirect vulnerability caused by user-supplied data being evaluated in Twig expressions and the acceptance of external URLs during redirect without origin validation.
What is the recommended action to mitigate CVE-2026-69087?
To mitigate the vulnerability, it is recommended to upgrade the Grav form plugin (getgrav/grav-plugin-form) to version 9.1.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.