Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1%
  • Veröffentlicht 09.02.2024 07:15:59
  • Zuletzt bearbeitet 16.06.2025 19:15:21

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.

Exploit
  • EPSS 2.81%
  • Veröffentlicht 18.07.2023 21:15:15
  • Zuletzt bearbeitet 21.11.2024 08:12:25

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduce...

Exploit
  • EPSS 2.07%
  • Veröffentlicht 14.06.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 08:06:52

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in...

Exploit
  • EPSS 4.52%
  • Veröffentlicht 14.06.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 08:07:16

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by ...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 14.06.2023 23:15:11
  • Zuletzt bearbeitet 21.11.2024 08:07:17

Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vulnerability that can be exploited by injecting a script into the "email" parameter of the request. Wh...

Exploit
  • EPSS 2.34%
  • Veröffentlicht 14.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:51

Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privil...

Exploit
  • EPSS 2.07%
  • Veröffentlicht 14.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:51

Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument passed to filte...

Exploit
  • EPSS 10.39%
  • Veröffentlicht 29.06.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 07:00:16

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

Exploit
  • EPSS 1.52%
  • Veröffentlicht 26.04.2022 16:15:47
  • Zuletzt bearbeitet 21.11.2024 06:40:11

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

Exploit
  • EPSS 1.8%
  • Veröffentlicht 15.03.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:39:46

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.