Getgrav

Grav

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 18.08.2026 11:19:45
  • Zuletzt bearbeitet 18.08.2026 14:18:11

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byte anywhere ...

  • EPSS 0.22%
  • Veröffentlicht 18.08.2026 11:19:45
  • Zuletzt bearbeitet 18.08.2026 15:17:14

Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the ac...

  • EPSS 0.19%
  • Veröffentlicht 18.08.2026 11:19:44
  • Zuletzt bearbeitet 18.08.2026 14:18:10

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account...

  • EPSS 0.25%
  • Veröffentlicht 18.08.2026 11:19:43
  • Zuletzt bearbeitet 18.08.2026 14:18:10

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attacker...

  • EPSS 0.22%
  • Veröffentlicht 18.08.2026 11:19:43
  • Zuletzt bearbeitet 19.08.2026 15:18:08

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the a...

  • EPSS 0.28%
  • Veröffentlicht 18.08.2026 11:19:42
  • Zuletzt bearbeitet 18.08.2026 15:17:14

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suffix' parameter...

  • EPSS 0.27%
  • Veröffentlicht 18.08.2026 11:19:41
  • Zuletzt bearbeitet 18.08.2026 14:18:10

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that ...

  • EPSS 0.29%
  • Veröffentlicht 18.08.2026 11:19:41
  • Zuletzt bearbeitet 18.08.2026 14:18:10

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameter...

  • EPSS 0.59%
  • Veröffentlicht 18.08.2026 11:19:40
  • Zuletzt bearbeitet 19.08.2026 15:18:08

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke ...

  • EPSS 0.17%
  • Veröffentlicht 18.08.2026 11:19:39
  • Zuletzt bearbeitet 18.08.2026 15:17:13

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaSc...