CVE-2026-55890
- EPSS 0.19%
- Veröffentlicht 10.07.2026 16:17:14
- Zuletzt bearbeitet 10.07.2026 19:17:26
Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-ac...
CVE-2026-55885
- EPSS 0.17%
- Veröffentlicht 10.07.2026 16:13:48
- Zuletzt bearbeitet 14.07.2026 02:16:56
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash ...
CVE-2026-53653
- EPSS 0.3%
- Veröffentlicht 10.07.2026 16:12:01
- Zuletzt bearbeitet 10.07.2026 21:16:54
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize i...
CVE-2026-61456
- EPSS 0.14%
- Veröffentlicht 10.07.2026 13:58:09
- Zuletzt bearbeitet 10.07.2026 17:41:47
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Securit...
CVE-2026-61450
- EPSS 0.25%
- Veröffentlicht 10.07.2026 13:58:08
- Zuletzt bearbeitet 10.07.2026 17:41:47
Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redacted facade a...
CVE-2026-61455
- EPSS 0.25%
- Veröffentlicht 10.07.2026 13:58:08
- Zuletzt bearbeitet 10.07.2026 17:41:47
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causi...
CVE-2026-58656
- EPSS 0.27%
- Veröffentlicht 08.07.2026 13:49:11
- Zuletzt bearbeitet 08.07.2026 17:17:25
Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious w...
CVE-2020-37256
- EPSS 0.17%
- Veröffentlicht 25.06.2026 21:41:00
- Zuletzt bearbeitet 27.06.2026 04:17:21
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malici...
CVE-2026-42844
- EPSS 0.34%
- Veröffentlicht 12.05.2026 21:43:18
- Zuletzt bearbeitet 19.05.2026 21:00:50
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created account wit...
CVE-2026-44738
- EPSS 0.28%
- Veröffentlicht 11.05.2026 17:16:34
- Zuletzt bearbeitet 14.05.2026 18:16:50
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secre...