Getgrav Grav vulnerabilities
166 known vulnerabilities affecting getgrav/grav.
Total CVEs
166
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL16HIGH78MEDIUM71LOW1
Vulnerabilities
Page 9 of 9
CVE-2025-66305P4MEDIUMCVSS 4.9≥ 1.7.48, < 1.8.0v1.8.0+1 more2025-12-01
CVE-2025-66305 [MEDIUM] CWE-248 CVE-2025-66305: Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability w
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel (/admin/config/system). Specifically, the Supported parameter fails to properly validate user input. If a malformed value is inserted—such as a single forward slash (/) or
ghsanvdosv
CVE-2026-55890P4MEDIUMCVSS 4.8≥ 0, < 2.0.0-rc.92026-06-18
CVE-2026-55890 [MEDIUM] CWE-79 Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
## Summary
The fix for **GHSA-r7fx-8g49-7hhr / CVE-2026-42841** (Stored XSS via Markdown media `attribute()` action) is incomplete. The maintainer patched `MediaObjectTrait::attribute()` to deny dangerous
ghsa
CVE-2024-35498P4MEDIUMCVSS 6.1v1.7.452025-01-06
CVE-2024-35498 [MEDIUM] CWE-79 CVE-2024-35498: A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
ghsanvdosv
CVE-2022-0743P4MEDIUMCVSS 4.6fixed in 1.7.312022-02-28
CVE-2022-0743 [MEDIUM] CWE-79 CVE-2022-0743: Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
ghsanvdosv
CVE-2026-75833P4MEDIUMCVSS 4.2fixed in 1.0.142026-08-18
CVE-2026-75833 [MEDIUM] CWE-601 CVE-2026-75833: The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before v
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes in special (http/https) schemes, so a returnTo value
nvd
CVE-2026-72701P4LOWCVSS 3.7fixed in 2.0.162026-08-25
CVE-2026-72701 [LOW] CWE-208 CVE-2026-72701: Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constan
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its
nvd
← Previous9 / 9