VulnSea

getgrav has 90 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 71 in the last 90 days against 4 in the 90 before. The busiest recent month was August 2026 with 33. The median CVSS is 6.8 (medium), with 6 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (23) and CWE-22 (11). Most affected products: getgrav/grav (52), grav (30), grav-plugin-admin (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.8
Publish → KEV
—
Last 90 days
71 prev 4

Products

  • getgrav/grav 52
  • grav 30
  • grav-plugin-admin 3
  • grav-plugin-api 3
  • grav-plugin-form 1
  • grav-plugin-shortcode-core 1
90
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

getgrav vulnerabilities

CVEs affecting getgrav, newest first. Open any entry for full detail, references, and exploit status.

90 CVEsRSS

GHSA-wvxr-6v52-gfmhHigh· 8.8
1mo ago

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

Duplicate Advisory: Remote code execution via .zip file upload in Grav CMS

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-cgvr-f65r-pjv3Medium· 5.4
1mo ago

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

Duplicate Advisory: Grav: Stored XSS via quoted-attribute bypass in detectXss

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-72832Medium· 5.4
1mo ago

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which c…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via NVD
CVE-2026-72819High· 8.8
1mo ago

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can byp…

▾ Twilightgetgrav · getgrav/gravEPSS 0.90%via NVD
GHSA-vj8j-973f-r65jHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-mmwh-j75q-gxp8High· 7.5
1mo ago

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-pp9r-ppc4-25w4High· 8.8
2mo ago

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-v626-428r-43p8High· 6.5
2mo ago

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-373m-p57p-8665Medium· 6.1
2mo ago

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

Duplicate Advisory: Grav: XSS Blueprint Validation Bypass via Twig String Concatenation

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-59193Medium· 4.9
2mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…

▾ Sunlitgetgrav · gravEPSS 0.60%via NVD
GHSA-4wj4-79rr-pvffMedium· 4.8
2mo ago

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

Duplicate Advisory: Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-32fw-h446-j4hhHigh· 6.5
3mo ago

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

Duplicate Advisory: Grav is Vulnerable to XXE via SVG Upload

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-55885Medium· 6.8
3mo ago

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

▾ Sunlitgetgrav · getgrav/gravEPSS 0.27%via GHSA
CVE-2026-55890Medium· 4.8
3mo ago

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-56701Medium· 6.5
4mo ago

Grav is Vulnerable to XXE via SVG Upload

Grav is Vulnerable to XXE via SVG Upload

▾ Sunlitgetgrav · getgrav/gravEPSS 0.40%via GHSA
CVE-2025-66312Medium· 5.4
10mo ago

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…

▾ Sunlitgetgrav · grav-plugin-adminEPSS 0.21%via NVD
CVE-2025-66311Medium· 5.4
10mo ago

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /ad…

▾ Sunlitgetgrav · grav-plugin-adminEPSS 0.21%via NVD
CVE-2025-66307Medium· 6.5
10mo ago

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "…

▾ Sunlitgetgrav · grav-plugin-adminEPSS 0.32%via NVD
CVE-2025-66306Medium· 4.3
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts…

▾ Sunlitgetgrav · gravEPSS 0.29%via NVD
CVE-2025-66304Medium· 6.2
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentiall…

▾ Sunlitgetgrav · gravEPSS 0.41%via NVD
CVE-2025-66303Medium· 4.9
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize i…

▾ Sunlitgetgrav · gravEPSS 0.39%via NVD
CVE-2025-66302Medium· 6.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server f…

▾ Sunlitgetgrav · gravEPSS 0.48%via NVD
CVE-2025-66301Critical· 9.6PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …

▾ Abyssalgetgrav · gravEPSS 1.3%via NVD
CVE-2025-66300High· 8.5
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), w…

▾ Twilightgetgrav · gravEPSS 0.45%via NVD
CVE-2025-66299High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…

▾ Twilightgetgrav · gravEPSS 0.60%via NVD
CVE-2025-66298High· 7.5
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side T…

▾ Twilightgetgrav · gravEPSS 0.38%via NVD
CVE-2025-66297High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…

▾ Twilightgetgrav · gravEPSS 0.78%via NVD
CVE-2025-66296High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…

▾ Twilightgetgrav · gravEPSS 0.32%via NVD
CVE-2025-66295High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat)…

▾ Twilightgetgrav · gravEPSS 0.55%via NVD
CVE-2025-66294High· 8.8PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …

▾ Midnightgetgrav · gravEPSS 2.8%via NVD
getgrav vulnerabilities (CVEs) — page 3 · VulnSea