CVE-2026-75830
- EPSS 0.28%
- Veröffentlicht 18.08.2026 11:19:42
- Zuletzt bearbeitet 08.09.2026 20:32:39
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batchCopy() method. An incomplete fix for GHSA-qjq4-jp55-4mx2 left the user-controlled 'suffix' parameter...
CVE-2026-75828
- EPSS 0.27%
- Veröffentlicht 18.08.2026 11:19:41
- Zuletzt bearbeitet 08.10.2026 16:17:40
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that ...
CVE-2026-75829
- EPSS 0.29%
- Veröffentlicht 18.08.2026 11:19:41
- Zuletzt bearbeitet 08.09.2026 20:32:39
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist pages with process.twig enabled. Attackers can submit crafted header and content parameter...
CVE-2026-75827
- EPSS 0.59%
- Veröffentlicht 18.08.2026 11:19:40
- Zuletzt bearbeitet 08.10.2026 16:17:40
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke ...
CVE-2026-75107
- EPSS 0.17%
- Veröffentlicht 18.08.2026 11:19:39
- Zuletzt bearbeitet 08.09.2026 20:32:39
Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaSc...
CVE-2026-74907
- EPSS 0.33%
- Veröffentlicht 18.08.2026 11:19:38
- Zuletzt bearbeitet 08.10.2026 16:17:40
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directories by exp...
CVE-2026-74908
- EPSS 0.18%
- Veröffentlicht 18.08.2026 11:19:38
- Zuletzt bearbeitet 08.09.2026 20:32:39
Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with api.media.writ...
CVE-2026-72833
- EPSS 0.26%
- Veröffentlicht 14.08.2026 11:35:39
- Zuletzt bearbeitet 30.09.2026 18:18:38
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypasses its declared scope cap on four isSuperAdmin()-gated write endpoints ...
CVE-2026-72832
- EPSS 0.18%
- Veröffentlicht 14.08.2026 11:35:38
- Zuletzt bearbeitet 08.10.2026 16:17:36
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which cannot cross t...
CVE-2026-72830
- EPSS 0.44%
- Veröffentlicht 14.08.2026 11:35:37
- Zuletzt bearbeitet 31.08.2026 20:38:54
Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. The scope cap is applied only inside requirePermission(), while the scheduler and ...