cbcvebase.

Getgrav Grav vulnerabilities

166 known vulnerabilities affecting getgrav/grav.

Total CVEs
166
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH78MEDIUM71LOW1

Vulnerabilities

Page 7 of 9
CVE-2026-56708P4MEDIUMCVSS 5.3fixed in 1.0.162026-08-25
CVE-2026-56708 [MEDIUM] CWE-367 CVE-2026-56708: Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delive Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups with public addresses and delivery lookups with private addresses to reach
nvd
CVE-2026-72820P4MEDIUMCVSS 4.9≥ 2.0.11, < 2.0.132026-08-14
CVE-2026-72820 [MEDIUM] CWE-22 CVE-2026-72820: Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.
nvd
CVE-2020-29556P4MEDIUM≥ 1.7.0-beta.1, ≤ 1.7.0-rc.17≥ 0, < 1.6.302022-05-24
CVE-2020-29556 [MEDIUM] CWE-22 Grav CMS Local File Injection Grav CMS Local File Injection The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.)
ghsaosv
CVE-2026-61456P4MEDIUMCVSS 4.6fixed in 1.0.32026-07-10
CVE-2026-61456 [MEDIUM] CWE-79 CVE-2026-61456: The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded thro The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Security::sanitizeSVG(), so an authenticated attacker with the api.media.write permission can upload an SVG c
nvd
CVE-2021-3818P4MEDIUMCVSS 5.3fixed in 1.7.222021-09-27
CVE-2021-3818 [MEDIUM] CWE-565 CVE-2021-3818: grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
ghsanvdosv
CVE-2026-75107P4MEDIUMCVSS 5.4fixed in 9.1.192026-08-18
CVE-2026-75107 [MEDIUM] CWE-79 CVE-2026-75107: Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option labels in form templates. Attackers with form authoring privileges can inject arbitrary HTML and JavaScript that executes for all form visitors through unescaped |raw filters and unquoted attributes.
nvd
CVE-2026-72702P4MEDIUMCVSS 5.4fixed in 2.0.162026-08-25
CVE-2026-72702 [MEDIUM] CWE-346 CVE-2026-72702: Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referr Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://exam
nvd
CVE-2026-61453P4MEDIUMCVSS 6.1fixed in 2.0.12026-07-15
CVE-2026-61453 [MEDIUM] CWE-79 CVE-2026-61453: Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint valida Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: true), an attacker with page-write API permission can use Twig's string concatenation operator (~) to dy
nvd
CVE-2025-65186P4MEDIUMCVSS 6.1v1.7.492025-12-02
CVE-2025-65186 [MEDIUM] CWE-79 CVE-2025-65186: Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated us Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface.
ghsanvdosv
CVE-2022-0970P4MEDIUMCVSS 5.4fixed in 1.7.312022-03-15
CVE-2022-0970 [MEDIUM] CWE-79 CVE-2022-0970: Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
ghsanvdosv
CVE-2026-64628P4MEDIUMCVSS 5.4≤ 6.2.12026-07-21
CVE-2026-64628 [MEDIUM] CWE-79 CVE-2026-64628: Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. Attackers with admin.pages permission can inject malicious JavaScript through shortcode attributes that execute in any
nvd
CVE-2025-66310P4MEDIUMCVSS 5.4fixed in 1.11.0-beta.12025-12-01
CVE-2025-66310 [MEDIUM] CWE-79 CVE-2025-66310: This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts
ghsanvdosv
CVE-2025-66312P4MEDIUMCVSS 5.4fixed in 1.11.0-beta.12025-12-01
CVE-2025-66312 [MEDIUM] CWE-79 CVE-2025-66312: This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/groups/Grupo endpoint of the Grav application. This vulnerability allows attackers to inject malicious
ghsanvdosv
CVE-2025-66308P4MEDIUMCVSS 5.4fixed in 1.11.0-beta.12025-12-01
CVE-2025-66308 [MEDIUM] CWE-79 CVE-2025-66308: This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/site endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts i
ghsanvdosv
CVE-2025-66311P4MEDIUMCVSS 5.4fixed in 1.11.0-beta.12025-12-01
CVE-2025-66311 [MEDIUM] CWE-79 CVE-2025-66311: This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts
ghsanvdosv
CVE-2026-85601P4MEDIUMCVSS 5.4fixed in 2.0.202026-09-04
CVE-2026-85601 [MEDIUM] CWE-79 CVE-2026-85601: Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the D Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme changelogs to execute arbitrary code in authenticated admin sessions without requiring site access.
nvd
CVE-2026-86197P4MEDIUMCVSS 5.1fixed in 2.0.202026-09-05
CVE-2026-86197 [MEDIUM] CWE-79 CVE-2026-86197: Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that all Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed f
nvd
CVE-2026-59193P4MEDIUMCVSS 4.9≥ 1.0.0, < 2.0.0v2.0.0-beta1+1 more2026-07-10
CVE-2026-59193 [MEDIUM] CWE-409 CVE-2026-59193: Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.
nvd
CVE-2026-44737P4MEDIUM≥ 0, < 1.7.49.52026-05-08
CVE-2026-44737 [MEDIUM] CWE-79 Grav: Stored XSS via page title (data[header][title]) in admin panel Grav: Stored XSS via page title (data[header][title]) in admin panel ### Summary _A Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows attackers to inject malicious scripts into the data[header][title] parameter._ --- ### Details Vulnerable Endpoint: GET /admin/pages/[page] Parameter: data[header]
ghsa
CVE-2026-74908P4MEDIUMCVSS 4.6fixed in 1.0.152026-08-18
CVE-2026-74908 [MEDIUM] CWE-79 CVE-2026-74908: Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exact extension 'svg', allowing .svgz and .xhtml files to bypass sanitization and be stored unsanitized. Attackers with api.media.write permission can upload files containing executable script payloads that execute in the site origin wh
nvd
Getgrav Grav vulnerabilities | cvebase