{"id":"CVE-2026-85598","title":"Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads","summary":"Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious …","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"getgrav","product":"grav","affected":["grav >= 2.0.0 <= 2.0.17"],"published":"2026-09-04","updated":"2026-09-14","sourceUpdated":"2026-09-14T20:16:58.137","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85598","references":[{"url":"https://github.com/getgrav/grav/security/advisories/GHSA-fg8g-663r-f366","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/grav-2.0.0-through-2.0.17-stored-xss-via-modular-pages","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00153,"epssPercentile":0.0486,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:19:23.236847Z"},"ingestedAt":"2026-09-06T01:47:58.057Z","slug":"CVE-2026-85598","body":"## Overview\n\nGrav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}