CVE-2023-34448
- EPSS 4.52%
- Veröffentlicht 14.06.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:07:16
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by ...
CVE-2023-34253
- EPSS 2.07%
- Veröffentlicht 14.06.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 08:06:52
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily subverted in...
CVE-2023-34252
- EPSS 2.07%
- Veröffentlicht 14.06.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:51
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument passed to filte...
CVE-2023-34251
- EPSS 2.34%
- Veröffentlicht 14.06.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:51
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privil...
CVE-2022-2073
- EPSS 9.05%
- Veröffentlicht 29.06.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:16
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
CVE-2022-1173
- EPSS 1.47%
- Veröffentlicht 26.04.2022 16:15:47
- Zuletzt bearbeitet 21.11.2024 06:40:11
stored xss in GitHub repository getgrav/grav prior to 1.7.33.
CVE-2022-0970
- EPSS 1.77%
- Veröffentlicht 15.03.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:46
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
CVE-2022-0743
- EPSS 1.34%
- Veröffentlicht 28.02.2022 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:39:18
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
CVE-2022-0268
- EPSS 1.42%
- Veröffentlicht 25.01.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:16
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
CVE-2021-3924
- EPSS 4.22%
- Veröffentlicht 05.11.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:22:47
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')