CVE-2026-86197
published 2026-09-05CVE-2026-86197: Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets…
PriorityP427medium5.1CVSS 4.0
AVNACLATNPRLUIPVCLVILVANSCLSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.26%
17.3th percentile
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| getgrav | grav | < 2.0.20 | 2.0.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping.
ghsa_unreviewed·2026-09-05
CVE-2026-86197 [MEDIUM] CWE-79 Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping.
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.
VulDB
GetGrav up to 2.0.19 Twig Sandbox Policy Grav/Common/Assets addJs cross site scripting
vuldb·2026-09-05·CVSS 5.1
CVE-2026-86197 [MEDIUM] GetGrav up to 2.0.19 Twig Sandbox Policy Grav/Common/Assets addJs cross site scripting
A vulnerability was found in GetGrav Grav up to 2.0.19 and classified as problematic. The impacted element is the function addJs of the file Grav/Common/Assets of the component Twig Sandbox Policy. Executing a manipulation can lead to cross site scripting.
This vulnerability is registered as CVE-2026-86197. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-05
Published