Grav has 3 CVEs on record. The median CVSS is 6.5 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Worst active — by depth score
CVE-2026-56700Critical· 9.8Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities54CVE-2026-56701Medium· 6.5Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files48CVE-2026-58657Medium· 4.8Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action38
Grav vulnerabilities
CVEs affecting Grav, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-58657Medium· 4.8PoCGrav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action
Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action. Prior media hardening rejects direct ?style= payloads and unsafe attribute() fa…
CVE-2026-56700Critical· 9.8Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allo…
CVE-2026-56701Medium· 6.5PoCGrav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simplexml_load_string without disabling exte…