← Browse

Getgrav

86 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-53654 MEDIUM 5.3 Grav — Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-control…● PoC 2026-08-19 CVE-2026-61607 MEDIUM 4.6 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC 2026-08-19 CVE-2026-61690 MEDIUM 6.5 Grav — Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Files… 2026-08-19 CVE-2026-61842 MEDIUM 6.5 Grav — Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('confi… 2026-08-19 CVE-2026-62666 HIGH 8.8 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior… 2026-08-19 CVE-2026-62667 HIGH 8.1 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior… 2026-08-19 CVE-2026-62668 CRITICAL 9.4 Grav — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC 2026-08-19 CVE-2026-62669 HIGH 7.4 Grav — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login pl… 2026-08-19 CVE-2026-62670 MEDIUM 6.3 Grav Plugin Flex Objects — Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Obje… 2026-08-19 CVE-2026-62671 MEDIUM 5.4 Grav Plugin Login — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login pl…● PoC 2026-08-19 CVE-2026-62672 MEDIUM 6 Grav — Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in sy…● PoC 2026-08-19 CVE-2026-62673 HIGH 8.2 Grav — Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt secur…● PoC 2026-08-19 CVE-2026-63407 HIGH 8.2 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior… 2026-08-19 CVE-2026-63408 HIGH 7.5 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prio… 2026-08-19 CVE-2026-64850 HIGH 8.7 Grav — Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Dat…● PoC 2026-08-19 CVE-2026-64851 HIGH 8.5 Grav Plugin Shortcode Core — Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilize…● PoC 2026-08-19 CVE-2026-64852 HIGH 8.7 Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC 2026-08-19 CVE-2026-74907 HIGH 8.2 Grav — Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that us… 2026-08-18 CVE-2026-74908 MEDIUM 5.1 Grav — Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks fo… 2026-08-18 CVE-2026-75107 MEDIUM 5.1 Grav — Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer t…● PoC 2026-08-18 CVE-2026-75827 CRITICAL 9.3 Grav — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function …● PoC 2026-08-18 CVE-2026-75828 CRITICAL 9.3 Grav — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpa…● PoC 2026-08-18 CVE-2026-75829 HIGH 8.6 Grav — grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing att… 2026-08-18 CVE-2026-75830 HIGH 7.1 Grav — grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vul…● PoC 2026-08-18 CVE-2026-75831 MEDIUM 5.1 Grav — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering…● PoC 2026-08-18 CVE-2026-75832 CRITICAL 9.3 Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) c… 2026-08-18 CVE-2026-75833 HIGH 8.6 Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0… 2026-08-18 CVE-2026-75834 MEDIUM 5.1 Grav — Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function … 2026-08-18 CVE-2026-75835 CRITICAL 9.3 Grav — Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in user…● PoC 2026-08-18 CVE-2026-75836 HIGH 8.7 Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to…● PoC 2026-08-18 CVE-2026-75837 CRITICAL 9.3 Grav — Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: ad…● PoC 2026-08-18 CVE-2026-72819 HIGH 8.7 Grav — Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings vali…● PoC 2026-08-14 CVE-2026-72820 MEDIUM 6.9 Grav — Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive…● PoC 2026-08-14 CVE-2026-72821 MEDIUM 5.1 Grav — Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggl… 2026-08-14 CVE-2026-72822 CRITICAL 9.3 Grav — The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope…● PoC 2026-08-14 CVE-2026-72823 MEDIUM 5.3 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoContro… 2026-08-14 CVE-2026-72824 CRITICAL 9.3 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesContr…● PoC 2026-08-14 CVE-2026-72825 HIGH 7.2 Grav — The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twi…● PoC 2026-08-14 CVE-2026-72826 CRITICAL 9.3 Grav — The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key … 2026-08-14 CVE-2026-72827 HIGH 8.7 Grav — Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that…● PoC 2026-08-14 CVE-2026-72828 HIGH 8.6 Grav — Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsCont… 2026-08-14 CVE-2026-72829 CRITICAL 9.3 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersContr…● PoC 2026-08-14 CVE-2026-72830 CRITICAL 9.3 Grav — Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gate…● PoC 2026-08-14 CVE-2026-72831 HIGH 8.7 Grav — The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerabi…● PoC 2026-08-14 CVE-2026-72832 MEDIUM 5.1 Grav — Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::d…● PoC 2026-08-14 CVE-2026-72833 HIGH 8.7 Grav — The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation v… 2026-08-14 CVE-2026-69087 HIGH 7.1 Grav Plugin Form — The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v…● PoC 2026-08-03 CVE-2026-69088 HIGH 8.6 Grav — Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in…● PoC 2026-08-03 CVE-2026-69089 HIGH 8.7 Grav — Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsaniti…● PoC 2026-08-03 CVE-2026-66400 MEDIUM 6.3 Grav — Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStor…● PoC 2026-07-29 CVE-2026-65608 HIGH 8.7 Grav — Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicD…● PoC 2026-07-23 CVE-2026-65895 HIGH 8.2 Grav — Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration…● PoC 2026-07-23 CVE-2026-65896 HIGH 7.1 Grav — Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug f…● PoC 2026-07-23 CVE-2026-65897 HIGH 8.7 Grav — Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), a…● PoC 2026-07-23 CVE-2026-65603 HIGH 8.7 Grav — The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authen…● PoC 2026-07-22 CVE-2026-64628 MEDIUM 5.1 Grav — Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS d…● PoC 2026-07-21 CVE-2026-65007 HIGH 8.7 Grav — The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocati…● PoC 2026-07-21 CVE-2026-65008 CRITICAL 9.3 Grav — Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system…● PoC 2026-07-21 CVE-2026-62230 HIGH 8.7 Grav — Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blockin…● PoC 2026-07-17 CVE-2026-62231 HIGH 8.6 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be c…● PoC 2026-07-17 CVE-2026-62232 CRITICAL 9.1 Grav — Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the rege…● PoC 2026-07-17 CVE-2026-62233 HIGH 8.7 Grav — grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa… 2026-07-17 CVE-2026-62234 HIGH 8.4 Grav — Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.…● PoC 2026-07-17 CVE-2026-62235 LOW 2.3 Grav — Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST A… 2026-07-17 CVE-2026-62236 LOW 2.3 Grav — grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regene…● PoC 2026-07-17 CVE-2026-62237 MEDIUM 6 Grav — Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace f…● PoC 2026-07-17 CVE-2026-62386 HIGH 8.2 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token=…● PoC 2026-07-17 CVE-2026-62387 HIGH 7.1 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its…● PoC 2026-07-17 CVE-2026-58655 HIGH 8.7 Grav — The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-…● PoC 2026-07-15 CVE-2026-61449 HIGH 7.1 Grav — Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound intr…● PoC 2026-07-15 CVE-2026-61451 CRITICAL 9.4 Grav — The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_b…● PoC 2026-07-15 CVE-2026-61452 MEDIUM 6.9 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerabi…● PoC 2026-07-15 CVE-2026-61453 MEDIUM 5.1 Grav — Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Secur…● PoC 2026-07-15 CVE-2026-61457 MEDIUM 5.3 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API …● PoC 2026-07-15 CVE-2026-61873 HIGH 7.2 Grav — Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename pa…● PoC 2026-07-15 CVE-2026-61454 HIGH 8.7 Grav — The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__…● PoC 2026-07-11 CVE-2026-53653 HIGH 8.7 Grav — Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to e… 2026-07-10 CVE-2026-55885 MEDIUM 6.8 Grav — Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can…● PoC 2026-07-10 CVE-2026-55890 MEDIUM 4.8 Grav — Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markd…● PoC 2026-07-10 CVE-2026-58492 CRITICAL 9.2 Grav — grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpol… 2026-07-10 CVE-2026-58493 MEDIUM 5.1 Grav — grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN stri…● PoC 2026-07-10 CVE-2026-59190 HIGH 8.7 Grav — grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages.…● PoC 2026-07-10 CVE-2026-59193 MEDIUM 6.9 Grav — Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill th…● PoC 2026-07-10 CVE-2026-61450 HIGH 7.1 Grav — Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone ab…● PoC 2026-07-10 CVE-2026-61455 HIGH 7.1 Grav — Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on u…● PoC 2026-07-10 CVE-2026-61456 MEDIUM 5.1 Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the PO…● PoC 2026-07-10