Skip to main content

Vendor archive

getgrav CVEs

Beta · best-effort

74 CVEs tagged to vendor getgrav5 Critical, 35 High, 34 Medium, 0 Low, 0 Unrated.

CVE-2026-59193

Published Jul 10, 2026

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direc…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2020-37256

Published Jun 25, 2026

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities ca…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-42844

Published May 12, 2026

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44738

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, du…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42843

Published May 11, 2026

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management. Prior to 1.0.0-beta.15…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42841

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rend…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42612

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary Ja…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42611

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can fu…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42610

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restri…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42609

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions)…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-42608

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-29924

Published Mar 30, 2026

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-47812

Published Jan 16, 2026

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. At…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66844

Published Dec 15, 2025

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PH…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66843

Published Dec 15, 2025

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65186

Published Dec 2, 2025

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66312

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Si…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66311

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Si…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66310

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Si…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66309

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66308

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Si…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66307

Published Dec 1, 2025

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeratio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66306

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66305

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66304

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all use…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 74 CVEsPage 1 of 3