Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 10.07.2026 13:58:08
  • Zuletzt bearbeitet 08.10.2026 16:17:25

Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causi...

  • EPSS 0.27%
  • Veröffentlicht 08.07.2026 13:49:11
  • Zuletzt bearbeitet 08.07.2026 17:17:25

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious w...

  • EPSS 0.17%
  • Veröffentlicht 25.06.2026 21:41:00
  • Zuletzt bearbeitet 08.10.2026 16:16:44

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malici...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 12.05.2026 21:43:18
  • Zuletzt bearbeitet 19.05.2026 21:00:50

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account wit...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 11.05.2026 17:16:34
  • Zuletzt bearbeitet 14.05.2026 18:16:50

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secre...

  • EPSS 0.15%
  • Veröffentlicht 11.05.2026 17:16:33
  • Zuletzt bearbeitet 13.05.2026 16:04:38

The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Tw...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 11.05.2026 16:17:34
  • Zuletzt bearbeitet 12.05.2026 16:16:44

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire system information available unde...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 11.05.2026 16:17:34
  • Zuletzt bearbeitet 12.05.2026 16:16:40

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue arises from a blacklist bypass in the detectXss() f...

  • EPSS 0.94%
  • Veröffentlicht 11.05.2026 16:17:34
  • Zuletzt bearbeitet 12.05.2026 14:51:21

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registration is enabl...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 11.05.2026 16:17:34
  • Zuletzt bearbeitet 12.05.2026 16:16:34

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML through Grav's Markdown media action syntax. The issue ...