CVE-2026-61842
- EPSS 0.32%
- Veröffentlicht 19.08.2026 15:23:27
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that object withou...
CVE-2026-61690
- EPSS 0.38%
- Veröffentlicht 19.08.2026 15:20:10
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or ...
CVE-2026-53654
- EPSS 0.39%
- Veröffentlicht 19.08.2026 15:15:30
- Zuletzt bearbeitet 09.09.2026 21:13:25
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location targ...
CVE-2026-75837
- EPSS 0.34%
- Veröffentlicht 18.08.2026 11:19:47
- Zuletzt bearbeitet 08.10.2026 16:17:41
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining ...
CVE-2026-75836
- EPSS 0.32%
- Veröffentlicht 18.08.2026 11:19:46
- Zuletzt bearbeitet 08.09.2026 20:32:39
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters me...
CVE-2026-75834
- EPSS 0.18%
- Veröffentlicht 18.08.2026 11:19:45
- Zuletzt bearbeitet 08.10.2026 16:17:41
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byte anywhere ...
CVE-2026-75835
- EPSS 0.22%
- Veröffentlicht 18.08.2026 11:19:45
- Zuletzt bearbeitet 08.09.2026 20:32:39
Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the ac...
CVE-2026-75833
- EPSS 0.19%
- Veröffentlicht 18.08.2026 11:19:44
- Zuletzt bearbeitet 08.09.2026 20:32:39
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account...
CVE-2026-75831
- EPSS 0.25%
- Veröffentlicht 18.08.2026 11:19:43
- Zuletzt bearbeitet 08.10.2026 16:17:40
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attacker...
CVE-2026-75832
- EPSS 0.22%
- Veröffentlicht 18.08.2026 11:19:43
- Zuletzt bearbeitet 08.09.2026 20:32:39
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the a...