CVE-2026-61454
- EPSS 0.24%
- Veröffentlicht 11.07.2026 13:01:06
- Zuletzt bearbeitet 13.07.2026 20:03:31
The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response...
CVE-2026-59190
- EPSS 0.22%
- Veröffentlicht 10.07.2026 17:17:02
- Zuletzt bearbeitet 10.07.2026 19:17:27
grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the su...
CVE-2026-59193
- EPSS 0.39%
- Veröffentlicht 10.07.2026 17:17:02
- Zuletzt bearbeitet 10.07.2026 20:16:48
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo wit...
CVE-2026-58493
- EPSS 0.29%
- Veröffentlicht 10.07.2026 16:24:32
- Zuletzt bearbeitet 13.07.2026 19:17:30
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly concatenating user-configurable YAML values from fields such as host, dbname, charset, server, database, directory, and file...
CVE-2026-58492
- EPSS 0.3%
- Veröffentlicht 10.07.2026 16:22:37
- Zuletzt bearbeitet 10.07.2026 17:35:11
grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-con...
CVE-2026-55890
- EPSS 0.19%
- Veröffentlicht 10.07.2026 16:17:14
- Zuletzt bearbeitet 10.07.2026 19:17:26
Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-ac...
CVE-2026-55885
- EPSS 0.17%
- Veröffentlicht 10.07.2026 16:13:48
- Zuletzt bearbeitet 14.07.2026 02:16:56
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash ...
CVE-2026-53653
- EPSS 0.3%
- Veröffentlicht 10.07.2026 16:12:01
- Zuletzt bearbeitet 10.07.2026 21:16:54
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize i...
CVE-2026-61456
- EPSS 0.14%
- Veröffentlicht 10.07.2026 13:58:09
- Zuletzt bearbeitet 10.07.2026 17:41:47
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Securit...
CVE-2026-61450
- EPSS 0.25%
- Veröffentlicht 10.07.2026 13:58:08
- Zuletzt bearbeitet 08.10.2026 16:17:25
Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redacted facade a...