---
id: CVE-2020-37256
title: >-
  Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin
  plugin page editor default security configuration
summary: >-
  Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin
  plugin page editor default security configuration. Privileged users with page
  editing capabilities can inject malicious scripts to execute arbitrary code
  and i…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: getgrav
product: grav
affected:
  - grav < 1.6.30
patched:
  - grav 1.6.30
published: '2026-06-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:16:44.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37256'
references:
  - url: 'https://github.com/getgrav/grav/security/advisories/GHSA-cvmr-6428-87w9'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/grav-cross-site-scripting-in-admin-plugin-page-editor
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-27T02:27:40.463020Z'
epss: 0.00287
epssPercentile: 0.19403
ingestedAt: '2026-10-08T16:52:14.693Z'
---

## Overview

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.

## Affected

- `grav < 1.6.30`

## Remediation

Upgrade past the affected range:

- `grav 1.6.30`
