Skip to main content

Vendor/product archive

getgrav / grav CVEs

Beta · best-effort

57 CVEs tagged to getgrav / grav4 Critical, 31 High, 22 Medium, 0 Low, 0 Unrated.

CVE-2022-0743

Published Feb 28, 2022

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0268

Published Jan 25, 2022

Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3924

Published Nov 5, 2021

grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3904

Published Oct 27, 2021

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3818

Published Sep 27, 2021

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29440

Published Apr 13, 2021

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig proce…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11529

Published Apr 4, 2020

Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-57 of 57 CVEsPage 3 of 3