What is CVE-2026-75107?
A vulnerability in Grav Form Plugin before version 9.1.19 allows attackers with form authoring privileges to inject arbitrary HTML and JavaScript due to improper escaping of field properties like prepend and append. This code executes for all form visitors, posing a significant cross-site scripting risk. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Grav Form Plugin-in 9.1.19-dan əvvəlki versiyalarında "prepend", "append" kimi sahə xüsusiyyətlərinin düzgün escap edilməməsi səbəbilə Zəiflik aşkarlanıb. Form müəllifi səlahiyyətinə malik hücumçular, bütün ziyarətçilər üçün icra oluna bilən ixtiyari HTML və JavaScript kodu inyeksiya edə bilər. Plugini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Grav Form Plugin are vulnerable to CVE-2026-75107?
All versions of the Grav Form Plugin before 9.1.19 are vulnerable.
What privilege must an attacker have to exploit CVE-2026-75107?
The attacker must have form authoring privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.