Getgrav

Grav

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 15.01.2026 23:25:54
  • Zuletzt bearbeitet 02.02.2026 16:16:15

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 15:38:46

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered

Exploit
  • EPSS 0.04%
  • Veröffentlicht 15.12.2025 00:00:00
  • Zuletzt bearbeitet 17.12.2025 15:39:29

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 02.12.2025 00:00:00
  • Zuletzt bearbeitet 03.12.2025 20:13:43

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when page...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 01.12.2025 22:06:27
  • Zuletzt bearbeitet 03.12.2025 21:56:09

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 01.12.2025 22:05:17
  • Zuletzt bearbeitet 03.12.2025 21:56:18

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[pa...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 01.12.2025 22:04:09
  • Zuletzt bearbeitet 03.12.2025 21:56:30

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[pa...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 01.12.2025 22:02:50
  • Zuletzt bearbeitet 03.12.2025 21:56:35

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 01.12.2025 22:00:42
  • Zuletzt bearbeitet 03.12.2025 21:56:43

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/si...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 01.12.2025 21:53:43
  • Zuletzt bearbeitet 03.12.2025 21:58:18

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Forgot Passwo...