CVE-2026-100672
- EPSS 0.45%
- Veröffentlicht 26.09.2026 13:23:36
- Zuletzt bearbeitet 28.09.2026 17:17:44
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the adm...
CVE-2026-100673
- EPSS 0.3%
- Veröffentlicht 26.09.2026 13:23:36
- Zuletzt bearbeitet 30.09.2026 21:16:54
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases af...
CVE-2026-100671
- EPSS 0.29%
- Veröffentlicht 26.09.2026 13:23:35
- Zuletzt bearbeitet 28.09.2026 19:16:45
Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig san...
CVE-2026-100669
- EPSS 0.44%
- Veröffentlicht 26.09.2026 13:23:34
- Zuletzt bearbeitet 30.09.2026 21:16:54
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, use...
CVE-2026-100670
- EPSS 0.3%
- Veröffentlicht 26.09.2026 13:23:34
- Zuletzt bearbeitet 30.09.2026 15:22:15
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation...
CVE-2026-100668
- EPSS 0.28%
- Veröffentlicht 26.09.2026 13:23:33
- Zuletzt bearbeitet 28.09.2026 17:17:44
Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r, vardump, json_encode, yaml_encode a...
CVE-2026-100667
- EPSS 0.31%
- Veröffentlicht 26.09.2026 13:23:32
- Zuletzt bearbeitet 28.09.2026 19:16:45
grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enable...
CVE-2026-92917
- EPSS 0.33%
- Veröffentlicht 17.09.2026 11:16:45
- Zuletzt bearbeitet 19.09.2026 03:17:18
Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox ...
CVE-2026-92916
- EPSS 0.35%
- Veröffentlicht 17.09.2026 11:16:44
- Zuletzt bearbeitet 30.09.2026 18:18:42
Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializePro...
CVE-2025-64059
- EPSS 0.23%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 13:42:45
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.