CVE-2026-86197
- EPSS 0.26%
- Veröffentlicht 05.09.2026 12:09:10
- Zuletzt bearbeitet 08.10.2026 16:17:55
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicio...
CVE-2026-85604
- EPSS 0.48%
- Veröffentlicht 04.09.2026 11:30:05
- Zuletzt bearbeitet 08.09.2026 20:05:53
Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort a...
CVE-2026-85602
- EPSS 0.26%
- Veröffentlicht 04.09.2026 11:30:04
- Zuletzt bearbeitet 08.09.2026 20:05:53
The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous a...
CVE-2026-85603
- EPSS 0.4%
- Veröffentlicht 04.09.2026 11:30:04
- Zuletzt bearbeitet 14.09.2026 20:16:58
Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal...
CVE-2026-85601
- EPSS 0.17%
- Veröffentlicht 04.09.2026 11:30:03
- Zuletzt bearbeitet 10.09.2026 16:17:59
Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme chan...
CVE-2026-85599
- EPSS 0.16%
- Veröffentlicht 04.09.2026 11:30:02
- Zuletzt bearbeitet 08.09.2026 20:05:53
Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitra...
CVE-2026-85600
- EPSS 0.17%
- Veröffentlicht 04.09.2026 11:30:02
- Zuletzt bearbeitet 08.09.2026 20:05:53
Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation template...
CVE-2026-85598
- EPSS 0.15%
- Veröffentlicht 04.09.2026 11:30:01
- Zuletzt bearbeitet 14.09.2026 20:16:58
Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code tha...
CVE-2026-80204
- EPSS 0.15%
- Veröffentlicht 26.08.2026 10:28:13
- Zuletzt bearbeitet 03.09.2026 05:15:14
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the...
CVE-2026-80203
- EPSS 0.39%
- Veröffentlicht 26.08.2026 10:28:12
- Zuletzt bearbeitet 03.09.2026 05:15:14
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rathe...