Grav · Grav-Plugin-Form · CVE-2026-86194
**Name of the Vulnerable Software and Affected Versions**
Grav Form Plugin versions prior to 9.1.22
**Description**
Insufficient page authorization verification occurs when resolving forms by name across pages. This allows anonymous visitors to execute form actions—such as saving, uploading, emailing, or calling—defined on unpublished or login-restricted pages. An attacker can trigger these actions by sending a POST request to any public page using the name of a restricted form.
**Recommendations**
Update Grav Form Plugin to version 9.1.22 or later.