getgrav has 90 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 71 in the last 90 days against 4 in the 90 before. The busiest recent month was August 2026 with 33. The median CVSS is 6.8 (medium), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (23) and CWE-22 (11). Most affected products: getgrav/grav (52), grav (30), grav-plugin-admin (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 71 prev 4
Weakness classes
Products
- getgrav/grav 52
- grav 30
- grav-plugin-admin 3
- grav-plugin-api 3
- grav-plugin-form 1
- grav-plugin-shortcode-core 1
Worst active — by depth score
CVE-2025-66301Critical· 9.6Grav is a file-based Web platform65CVE-2026-85604High· 8.8Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter61CVE-2026-75827High· 8.8Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist61CVE-2025-66294High· 8.8Grav is a file-based Web platform61CVE-2026-86196High· 8.7Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains60
getgrav vulnerabilities
CVEs affecting getgrav, newest first. Open any entry for full detail, references, and exploit status.
90 CVEsRSS
GHSA-wvxr-6v52-gfmhHigh· 8.8Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS
GHSA-cgvr-f65r-pjv3Medium· 5.4Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss
CVE-2026-72832Medium· 5.4Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…
CVE-2026-72819High· 8.8Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…
GHSA-vj8j-973f-r65jHigh· 8.1Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
GHSA-mmwh-j75q-gxp8High· 7.5Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
GHSA-pp9r-ppc4-25w4High· 8.8Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
GHSA-v626-428r-43p8High· 6.5Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
GHSA-373m-p57p-8665Medium· 6.1Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
CVE-2026-59193Medium· 4.9Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…
GHSA-4wj4-79rr-pvffMedium· 4.8Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
GHSA-32fw-h446-j4hhHigh· 6.5Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload
CVE-2026-55885Medium· 6.8Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
CVE-2026-55890Medium· 4.8Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
CVE-2026-56701Medium· 6.5Grav is Vulnerable to XXE via SVG Upload
Grav is Vulnerable to XXE via SVG Upload
CVE-2025-66312Medium· 5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…
CVE-2025-66311Medium· 5.4This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…
CVE-2025-66307Medium· 6.5This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "…
CVE-2025-66306Medium· 4.3Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts…
CVE-2025-66304Medium· 6.2Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentiall…
CVE-2025-66303Medium· 4.9Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize i…
CVE-2025-66302Medium· 6.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server f…
CVE-2025-66301Critical· 9.6PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …
CVE-2025-66300High· 8.5Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), w…
CVE-2025-66299High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…
CVE-2025-66298High· 7.5Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side T…
CVE-2025-66297High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…
CVE-2025-66296High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…
CVE-2025-66295High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat)…
CVE-2025-66294High· 8.8PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …