Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 17.07.2026 00:07:08
  • Zuletzt bearbeitet 08.10.2026 16:17:26

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim'...

  • EPSS 0.22%
  • Veröffentlicht 17.07.2026 00:07:07
  • Zuletzt bearbeitet 21.07.2026 02:16:23

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owni...

  • EPSS 0.28%
  • Veröffentlicht 17.07.2026 00:07:06
  • Zuletzt bearbeitet 08.10.2026 16:17:26

Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case-insensitiv...

  • EPSS 0.26%
  • Veröffentlicht 15.07.2026 11:25:56
  • Zuletzt bearbeitet 15.07.2026 19:50:11

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form ...

  • EPSS 0.46%
  • Veröffentlicht 15.07.2026 11:25:46
  • Zuletzt bearbeitet 15.07.2026 19:50:11

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTEN...

  • EPSS 0.19%
  • Veröffentlicht 15.07.2026 11:25:45
  • Zuletzt bearbeitet 15.07.2026 19:50:11

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, acc...

  • EPSS 0.16%
  • Veröffentlicht 15.07.2026 11:25:45
  • Zuletzt bearbeitet 08.10.2026 16:17:25

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: tr...

  • EPSS 0.24%
  • Veröffentlicht 15.07.2026 11:25:44
  • Zuletzt bearbeitet 15.07.2026 19:50:11

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/http...

  • EPSS 0.25%
  • Veröffentlicht 15.07.2026 11:25:43
  • Zuletzt bearbeitet 08.10.2026 16:17:24

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejec...

  • EPSS 1.08%
  • Veröffentlicht 15.07.2026 11:25:34
  • Zuletzt bearbeitet 15.07.2026 21:02:13

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter val...