Skip to main content

Vendor/product archive

getgrav / grav CVEs

Beta · best-effort

57 CVEs tagged to getgrav / grav4 Critical, 31 High, 22 Medium, 0 Low, 0 Unrated.

CVE-2025-66296

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66295

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing p…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66294

Published Dec 1, 2025

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor per…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-63593

Published Nov 3, 2025

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50286

Published Aug 6, 2025

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uplo…

CVSS 8.1 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-46198

Published Jul 25, 2025

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-46199

Published Jul 25, 2025

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-35498

Published Jan 6, 2025

A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34082

Published May 15, 2024

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav u…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28119

Published Mar 21, 2024

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can red…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28118

Published Mar 21, 2024

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can red…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28117

Published Mar 21, 2024

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28116

Published Mar 21, 2024

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authentica…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27921

Published Mar 21, 2024

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling at…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27923

Published Mar 21, 2024

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inad…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31506

Published Feb 9, 2024

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37897

Published Jul 18, 2023

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|fi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34452

Published Jun 14, 2023

Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vulnerability that can be exploi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34448

Published Jun 14, 2023

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34253

Published Jun 14, 2023

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34252

Published Jun 14, 2023

Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34251

Published Jun 14, 2023

Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2073

Published Jun 29, 2022

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1173

Published Apr 26, 2022

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0970

Published Mar 15, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 57 CVEsPage 2 of 3