CVE-2022-0743
Published Feb 28, 2022Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Vendor/product archive
57 CVEs tagged to getgrav / grav — 4 Critical, 31 High, 22 Medium, 0 Low, 0 Unrated.
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig proce…
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.