getgrav/grav vulnerabilities
CVEs whose affected-version data names the getgrav/grav package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
52 CVEsRSS
GHSA-2rhw-8953-48q3High· 5.9Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
GHSA-q8cg-5m48-5c25Medium· 7.6Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL
Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL
CVE-2026-75837Critical· 9.1Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…
CVE-2026-75834Medium· 5.4Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…
CVE-2026-75831High· 7.6Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…
CVE-2026-75828High· 8.7Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…
CVE-2026-75827High· 8.8PoCGrav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…
CVE-2026-74907Medium· 5.9Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…
GHSA-wvxr-6v52-gfmhHigh· 8.8Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
GHSA-cgvr-f65r-pjv3Medium· 5.4Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
CVE-2026-72832Medium· 5.4Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…
CVE-2026-72819High· 8.8Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…
GHSA-vj8j-973f-r65jHigh· 8.1Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
GHSA-mmwh-j75q-gxp8High· 7.5Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
GHSA-pp9r-ppc4-25w4High· 8.8Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
GHSA-v626-428r-43p8High· 6.5Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
GHSA-373m-p57p-8665Medium· 6.1Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
GHSA-4wj4-79rr-pvffMedium· 4.8Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-55885Medium· 6.8Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVE-2026-55890Medium· 4.8Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
Grav is Vulnerable to XXE via SVG Upload