
CVE-2026-42842 The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugi… https://www.cve.org/CVERecord?id=CVE-2026-42842
Post summary
The text announces a stored XSS vulnerability in the Grav CMS Form plugin prior to version 9.1.0, without mentioning PoC, exploit, patch, or active exploitation.
