Getgrav

Grav

177 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 21.07.2026 11:39:57
  • Zuletzt bearbeitet 08.10.2026 16:17:28

Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() with...

  • EPSS 0.27%
  • Veröffentlicht 21.07.2026 11:39:56
  • Zuletzt bearbeitet 23.07.2026 15:17:46

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on on...

  • EPSS 0.15%
  • Veröffentlicht 21.07.2026 11:39:55
  • Zuletzt bearbeitet 23.07.2026 19:17:03

Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. Attackers with ad...

  • EPSS 0.26%
  • Veröffentlicht 17.07.2026 00:07:14
  • Zuletzt bearbeitet 17.07.2026 15:44:29

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accept...

  • EPSS 0.27%
  • Veröffentlicht 17.07.2026 00:07:13
  • Zuletzt bearbeitet 23.07.2026 20:17:19

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logge...

  • EPSS 0.1%
  • Veröffentlicht 17.07.2026 00:07:11
  • Zuletzt bearbeitet 17.07.2026 15:44:29

grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:07:11
  • Zuletzt bearbeitet 08.10.2026 16:17:27

Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_conten...

  • EPSS 0.17%
  • Veröffentlicht 17.07.2026 00:07:10
  • Zuletzt bearbeitet 17.07.2026 15:44:29

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. A...

  • EPSS 0.25%
  • Veröffentlicht 17.07.2026 00:07:09
  • Zuletzt bearbeitet 17.07.2026 19:17:18

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin account...

  • EPSS 0.3%
  • Veröffentlicht 17.07.2026 00:07:09
  • Zuletzt bearbeitet 23.07.2026 20:17:19

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local fi...