VulnSea

getgrav/grav vulnerabilities

CVEs whose affected-version data names the getgrav/grav package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

52 CVEsRSS

GHSA-2rhw-8953-48q3High· 5.9
1mo ago

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-q8cg-5m48-5c25Medium· 7.6
1mo ago

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-75837Critical· 9.1
1mo ago

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…

▾ Midnightgetgrav · getgrav/gravEPSS 0.49%via NVD
CVE-2026-75834Medium· 5.4
1mo ago

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.26%via NVD
CVE-2026-75831High· 7.6
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…

▾ Twilightgetgrav · getgrav/gravEPSS 0.35%via NVD
CVE-2026-75828High· 8.7
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…

▾ Twilightgetgrav · getgrav/gravEPSS 0.39%via NVD
CVE-2026-75827High· 8.8PoC
1mo ago

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…

▾ Midnightgetgrav · getgrav/gravEPSS 0.86%via NVD
CVE-2026-74907Medium· 5.9
1mo ago

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.43%via NVD
GHSA-wvxr-6v52-gfmhHigh· 8.8
1mo ago

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-cgvr-f65r-pjv3Medium· 5.4
1mo ago

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-72832Medium· 5.4
1mo ago

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via NVD
CVE-2026-72819High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via NVD
GHSA-vj8j-973f-r65jHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-mmwh-j75q-gxp8High· 7.5
1mo ago

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-pp9r-ppc4-25w4High· 8.8
2mo ago

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-v626-428r-43p8High· 6.5
2mo ago

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-373m-p57p-8665Medium· 6.1
2mo ago

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-4wj4-79rr-pvffMedium· 4.8
2mo ago

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-32fw-h446-j4hhHigh· 6.5
3mo ago

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-55885Medium· 6.8
3mo ago

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

▾ Sunlitgetgrav · getgrav/gravEPSS 0.27%via GHSA
CVE-2026-55890Medium· 4.8
3mo ago

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-56701Medium· 6.5
4mo ago

Grav is Vulnerable to XXE via SVG Upload

Grav is Vulnerable to XXE via SVG Upload

▾ Sunlitgetgrav · getgrav/gravEPSS 0.40%via GHSA
getgrav/grav vulnerabilities (CVEs) — page 2 · VulnSea