CVE-2026-42844
- EPSS 0.34%
- Veröffentlicht 12.05.2026 21:43:18
- Zuletzt bearbeitet 19.05.2026 21:00:50
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account wit...
CVE-2026-44738
- EPSS 0.28%
- Veröffentlicht 11.05.2026 17:16:34
- Zuletzt bearbeitet 14.05.2026 18:16:50
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secre...
CVE-2026-42842
- EPSS 0.15%
- Veröffentlicht 11.05.2026 17:16:33
- Zuletzt bearbeitet 13.05.2026 16:04:38
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Tw...
CVE-2026-42841
- EPSS 0.4%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 16:16:34
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML through Grav's Markdown media action syntax. The issue ...
CVE-2026-42613
- EPSS 0.94%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 14:51:21
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registration is enabl...
CVE-2026-42612
- EPSS 0.24%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 16:16:40
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue arises from a blacklist bypass in the detectXss() f...
CVE-2026-42611
- EPSS 0.3%
- Veröffentlicht 11.05.2026 16:17:34
- Zuletzt bearbeitet 12.05.2026 16:16:44
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire system information available unde...
CVE-2026-42610
- EPSS 0.29%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 12.05.2026 16:16:49
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programm...
CVE-2026-42609
- EPSS 0.46%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 14.05.2026 18:16:48
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary administrator. B...
CVE-2026-42608
- EPSS 0.52%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 13.05.2026 18:39:05
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traver...