Grav Form 插件在 9.1.22 之前的版本中,在跨页面按名称解析表单时未能验证页面授权,使得匿名用户能够执行定义在需要登录或尚未发布页面上的表单动作。攻击者可以向任何包含受限表单名称的公开页面发送 POST 请求,从而无需身份验证即可触发保存、上传、发送邮件或调用等动作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| getgrav | grav-plugin-form | < 9.1.22 |
affected |
9.1.22 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-form | 0 ~ 9.1.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86196 | 8.7 HIGH | Grav API Plugin before 1.0.20 Authentication Bypass via Host Header |
| CVE-2026-86195 | 8.7 HIGH | grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag |
| CVE-2026-86193 | 8.7 HIGH | Grav API Plugin Authentication Bypass via Group-Inherited Super |
| CVE-2026-86197 | 5.1 MEDIUM | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox |
No comments yet