VulnSea

Grav vulnerabilities

CVEs whose affected-version data names the Grav package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-92916High· 7.5
5d ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: …

Twilightgetgrav · gravEPSS 0.35%via NVD
CVE-2026-92917High· 7.5PoC
5d ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determ…

Midnightgetgrav · gravEPSS 0.33%via NVD
CVE-2025-64059Low· 1.8PoC
1w ago

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Twilightgetgrav · GravEPSS 0.23%via NVD
CVE-2026-86197Medium· 5.1
2w ago

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by regist…

Sunlitgetgrav · gravEPSS 0.26%via NVD
CVE-2026-85603Medium· 6.5
2w ago

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply direct…

Sunlitgetgrav · gravEPSS 0.40%via NVD
CVE-2026-85601Medium· 5.4
2w ago

Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components

Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin …

Sunlitgetgrav · gravEPSS 0.17%via NVD
CVE-2026-85604High· 8.8PoC
2w ago

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|re…

Midnightgetgrav · gravEPSS 0.48%via NVD
CVE-2026-85598Medium· 6.4
2w ago

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious …

Sunlitgetgrav · gravEPSS 0.15%via NVD
CVE-2026-62672Medium· 6.0PoC
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). Wh…

Twilightgetgrav · gravEPSS 0.39%via NVD
CVE-2026-59193Medium· 4.9
2mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…

Sunlitgetgrav · gravEPSS 0.60%via NVD
Grav vulnerabilities (CVEs) · VulnSea