CVE-2026-42608
- EPSS 0.52%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 13.05.2026 18:39:05
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker can traver...
CVE-2026-42609
- EPSS 0.46%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 14.05.2026 18:16:48
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary administrator. B...
CVE-2026-42610
- EPSS 0.29%
- Veröffentlicht 11.05.2026 16:17:33
- Zuletzt bearbeitet 12.05.2026 16:16:49
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker can programm...
CVE-2026-42607
- EPSS 3.93%
- Veröffentlicht 11.05.2026 16:17:32
- Zuletzt bearbeitet 12.05.2026 14:51:21
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the system attem...
CVE-2026-29924
- EPSS 0.34%
- Veröffentlicht 30.03.2026 00:00:00
- Zuletzt bearbeitet 06.04.2026 15:58:27
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
CVE-2021-47812
- EPSS 2.06%
- Veröffentlicht 15.01.2026 23:25:54
- Zuletzt bearbeitet 02.02.2026 16:16:15
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code through the scheduler endpoint. Attackers can exploit the admin-nonce parameter to inject base64-encoded ...
CVE-2025-66843
- EPSS 0.16%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 15:39:29
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. ...
CVE-2025-66844
- EPSS 0.28%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 17.12.2025 15:38:46
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
CVE-2025-65186
- EPSS 0.22%
- Veröffentlicht 02.12.2025 00:00:00
- Zuletzt bearbeitet 03.12.2025 20:13:43
Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when page...
CVE-2025-66312
- EPSS 0.21%
- Veröffentlicht 01.12.2025 22:06:27
- Zuletzt bearbeitet 26.09.2026 00:10:00
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/...