Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 25.08.2026 01:30:31
  • Zuletzt bearbeitet 08.10.2026 16:17:43

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to ext...

  • EPSS 0.24%
  • Veröffentlicht 25.08.2026 01:30:31
  • Zuletzt bearbeitet 08.10.2026 16:17:43

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to...

  • EPSS 0.36%
  • Veröffentlicht 25.08.2026 01:30:26
  • Zuletzt bearbeitet 31.08.2026 20:52:56

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig ex...

  • EPSS 0.1%
  • Veröffentlicht 25.08.2026 01:30:25
  • Zuletzt bearbeitet 08.10.2026 16:17:34

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing deli...

  • EPSS 0.18%
  • Veröffentlicht 25.08.2026 01:30:23
  • Zuletzt bearbeitet 08.10.2026 16:17:34

Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences t...

  • EPSS 0.26%
  • Veröffentlicht 25.08.2026 01:30:22
  • Zuletzt bearbeitet 16.09.2026 13:42:44

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login...

  • EPSS 0.24%
  • Veröffentlicht 25.08.2026 01:30:21
  • Zuletzt bearbeitet 08.10.2026 16:17:33

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration array...

  • EPSS 0.21%
  • Veröffentlicht 25.08.2026 01:30:21
  • Zuletzt bearbeitet 31.08.2026 20:52:56

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to ...

  • EPSS 0.31%
  • Veröffentlicht 25.08.2026 01:30:18
  • Zuletzt bearbeitet 08.10.2026 16:17:33

Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page auth...

  • EPSS 0.14%
  • Veröffentlicht 25.08.2026 01:30:14
  • Zuletzt bearbeitet 31.08.2026 20:52:56

Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory...