PT-2026-86419 · Grav · Grav-Plugin-Form

·

CVE-2026-86194

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Grav Form Plugin versions prior to 9.1.22
Description Insufficient page authorization verification occurs when resolving forms by name across pages. This allows anonymous visitors to execute form actions—such as saving, uploading, emailing, or calling—defined on unpublished or login-restricted pages. An attacker can trigger these actions by sending a POST request to any public page using the name of a restricted form.
Recommendations Update Grav Form Plugin to version 9.1.22 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86194

Affected Products

Grav-Plugin-Form