Getgrav

Grav

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 01.12.2025 21:03:07
  • Zuletzt bearbeitet 04.12.2025 18:33:10

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create ...

Exploit
  • EPSS 2.86%
  • Veröffentlicht 01.12.2025 20:52:08
  • Zuletzt bearbeitet 04.12.2025 18:36:15

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, under certain...

  • EPSS 0.54%
  • Veröffentlicht 01.12.2025 20:46:56
  • Zuletzt bearbeitet 04.12.2025 18:34:22

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat), Grav writes...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 03.11.2025 00:00:00
  • Zuletzt bearbeitet 07.11.2025 18:33:34

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

Exploit
  • EPSS 9.32%
  • Veröffentlicht 06.08.2025 00:00:00
  • Zuletzt bearbeitet 07.11.2025 19:18:37

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitr...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 25.07.2025 18:15:26
  • Zuletzt bearbeitet 15.08.2025 14:32:27

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

Exploit
  • EPSS 0.63%
  • Veröffentlicht 25.07.2025 00:00:00
  • Zuletzt bearbeitet 20.08.2025 20:05:24

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element

Exploit
  • EPSS 0.38%
  • Veröffentlicht 06.01.2025 19:15:12
  • Zuletzt bearbeitet 17.04.2025 02:36:22

A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Exploit
  • EPSS 3.05%
  • Veröffentlicht 15.05.2024 17:15:12
  • Zuletzt bearbeitet 02.01.2025 23:06:29

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hash...

Exploit
  • EPSS 1.22%
  • Veröffentlicht 21.03.2024 22:15:12
  • Zuletzt bearbeitet 02.01.2025 22:59:47

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI...