Skip to main content

Vendor/product archive

getgrav / grav CVEs

Beta · best-effort

57 CVEs tagged to getgrav / grav4 Critical, 31 High, 22 Medium, 0 Low, 0 Unrated.

CVE-2026-59193

Published Jul 10, 2026

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direc…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2020-37256

Published Jun 25, 2026

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities ca…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-42844

Published May 12, 2026

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44738

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, du…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42841

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rend…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42612

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary Ja…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42611

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can fu…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42610

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restri…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42609

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions)…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-42608

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-29924

Published Mar 30, 2026

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-47812

Published Jan 16, 2026

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. At…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66844

Published Dec 15, 2025

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PH…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66843

Published Dec 15, 2025

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65186

Published Dec 2, 2025

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66306

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66305

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66304

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all use…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66303

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters.…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66302

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative pri…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66301

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an ed…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66300

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includ…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66299

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permiss…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66298

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66297

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the pag…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 57 CVEsPage 1 of 3