Getgrav

Grav

142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 15.07.2026 11:25:45
  • Zuletzt bearbeitet 15.07.2026 19:50:11

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, acc...

  • EPSS 0.16%
  • Veröffentlicht 15.07.2026 11:25:45
  • Zuletzt bearbeitet 15.07.2026 19:50:11

Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: tr...

  • EPSS 0.24%
  • Veröffentlicht 15.07.2026 11:25:44
  • Zuletzt bearbeitet 15.07.2026 19:50:11

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/http...

  • EPSS 0.25%
  • Veröffentlicht 15.07.2026 11:25:43
  • Zuletzt bearbeitet 15.07.2026 19:50:11

Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejec...

  • EPSS 1.08%
  • Veröffentlicht 15.07.2026 11:25:34
  • Zuletzt bearbeitet 15.07.2026 21:02:13

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter val...

  • EPSS 0.24%
  • Veröffentlicht 11.07.2026 13:01:06
  • Zuletzt bearbeitet 13.07.2026 20:03:31

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response...

  • EPSS 0.22%
  • Veröffentlicht 10.07.2026 17:17:02
  • Zuletzt bearbeitet 10.07.2026 19:17:27

grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the su...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 10.07.2026 17:17:02
  • Zuletzt bearbeitet 10.07.2026 20:16:48

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo wit...

  • EPSS 0.29%
  • Veröffentlicht 10.07.2026 16:24:32
  • Zuletzt bearbeitet 13.07.2026 19:17:30

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly concatenating user-configurable YAML values from fields such as host, dbname, charset, server, database, directory, and file...

  • EPSS 0.3%
  • Veröffentlicht 10.07.2026 16:22:37
  • Zuletzt bearbeitet 10.07.2026 17:35:11

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-con...