Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 05.09.2026 12:09:10
  • Zuletzt bearbeitet 08.10.2026 16:17:55

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicio...

  • EPSS 0.48%
  • Veröffentlicht 04.09.2026 11:30:05
  • Zuletzt bearbeitet 08.09.2026 20:05:53

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort a...

  • EPSS 0.26%
  • Veröffentlicht 04.09.2026 11:30:04
  • Zuletzt bearbeitet 08.09.2026 20:05:53

The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous a...

  • EPSS 0.4%
  • Veröffentlicht 04.09.2026 11:30:04
  • Zuletzt bearbeitet 14.09.2026 20:16:58

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal...

  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 11:30:03
  • Zuletzt bearbeitet 10.09.2026 16:17:59

Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme chan...

  • EPSS 0.16%
  • Veröffentlicht 04.09.2026 11:30:02
  • Zuletzt bearbeitet 08.09.2026 20:05:53

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitra...

  • EPSS 0.17%
  • Veröffentlicht 04.09.2026 11:30:02
  • Zuletzt bearbeitet 08.09.2026 20:05:53

Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation template...

  • EPSS 0.15%
  • Veröffentlicht 04.09.2026 11:30:01
  • Zuletzt bearbeitet 14.09.2026 20:16:58

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code tha...

  • EPSS 0.15%
  • Veröffentlicht 26.08.2026 10:28:13
  • Zuletzt bearbeitet 03.09.2026 05:15:14

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the...

  • EPSS 0.39%
  • Veröffentlicht 26.08.2026 10:28:12
  • Zuletzt bearbeitet 03.09.2026 05:15:14

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rathe...