CVE-2020-36955
- EPSS 0.01%
- Veröffentlicht 26.01.2026 17:42:45
- Zuletzt bearbeitet 27.01.2026 14:59:34
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in...
CVE-2021-47812
- EPSS 0.16%
- Veröffentlicht 15.01.2026 23:25:54
- Zuletzt bearbeitet 02.02.2026 16:16:15
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded ...
CVE-2020-29553
- EPSS 0.15%
- Veröffentlicht 15.03.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:24:11
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
CVE-2020-29555
- EPSS 4.16%
- Veröffentlicht 15.03.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:11
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticat...
CVE-2020-29556
- EPSS 0.11%
- Veröffentlicht 15.03.2021 18:15:17
- Zuletzt bearbeitet 21.11.2024 05:24:11
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated...
CVE-2019-16126
- EPSS 0.61%
- Veröffentlicht 09.09.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:06
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
CVE-2018-5233
- EPSS 18.83%
- Veröffentlicht 19.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:23
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.