Impact
The vulnerability is a stored cross‑site scripting flaw in the Grav Form plugin. Radio and toggle field option labels are rendered using the Twig |raw filter, so an attacker with form authoring permissions can inject HTML or JavaScript that executes when visitors or administrators view the form. This can lead to defacement, theft of session cookies, or other client‑side attacks but does not provide server‑side code execution or privilege escalation.
Affected Systems
The issue affects the Grav content management system, specifically the Grav Form plugin in all versions prior to 9.1.15. Users running any older Grav Form plugin on a Grav site are susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers must have form authoring rights and edit a form’s option labels; the flaw is exploitable once those privileges exist, making it a reasonable risk in shared or multi‑user environments.
OpenCVE Enrichment