Getgrav
86 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-53654
MEDIUM 5.3
Grav — Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-control…● PoC
2026-08-19
CVE-2026-61607
MEDIUM 4.6
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC
2026-08-19
CVE-2026-61690
MEDIUM 6.5
Grav — Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Files…
2026-08-19
CVE-2026-61842
MEDIUM 6.5
Grav — Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('confi…
2026-08-19
CVE-2026-62666
HIGH 8.8
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…
2026-08-19
CVE-2026-62667
HIGH 8.1
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…
2026-08-19
CVE-2026-62668
CRITICAL 9.4
Grav — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC
2026-08-19
CVE-2026-62669
HIGH 7.4
Grav — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login pl…
2026-08-19
CVE-2026-62670
MEDIUM 6.3
Grav Plugin Flex Objects — Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Obje…
2026-08-19
CVE-2026-62671
MEDIUM 5.4
Grav Plugin Login — Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login pl…● PoC
2026-08-19
CVE-2026-62672
MEDIUM 6
Grav — Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in sy…● PoC
2026-08-19
CVE-2026-62673
HIGH 8.2
Grav — Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt secur…● PoC
2026-08-19
CVE-2026-63407
HIGH 8.2
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…
2026-08-19
CVE-2026-63408
HIGH 7.5
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prio…
2026-08-19
CVE-2026-64850
HIGH 8.7
Grav — Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Dat…● PoC
2026-08-19
CVE-2026-64851
HIGH 8.5
Grav Plugin Shortcode Core — Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilize…● PoC
2026-08-19
CVE-2026-64852
HIGH 8.7
Grav Plugin Api — Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior…● PoC
2026-08-19
CVE-2026-74907
HIGH 8.2
Grav — Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that us…
2026-08-18
CVE-2026-74908
MEDIUM 5.1
Grav — Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks fo…
2026-08-18
CVE-2026-75107
MEDIUM 5.1
Grav — Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer t…● PoC
2026-08-18
CVE-2026-75827
CRITICAL 9.3
Grav — Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function …● PoC
2026-08-18
CVE-2026-75828
CRITICAL 9.3
Grav — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpa…● PoC
2026-08-18
CVE-2026-75829
HIGH 8.6
Grav — grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing att…
2026-08-18
CVE-2026-75830
HIGH 7.1
Grav — grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vul…● PoC
2026-08-18
CVE-2026-75831
MEDIUM 5.1
Grav — Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering…● PoC
2026-08-18
CVE-2026-75832
CRITICAL 9.3
Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) c…
2026-08-18
CVE-2026-75833
HIGH 8.6
Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0…
2026-08-18
CVE-2026-75834
MEDIUM 5.1
Grav — Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function …
2026-08-18
CVE-2026-75835
CRITICAL 9.3
Grav — Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in user…● PoC
2026-08-18
CVE-2026-75836
HIGH 8.7
Grav — The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to…● PoC
2026-08-18
CVE-2026-75837
CRITICAL 9.3
Grav — Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: ad…● PoC
2026-08-18
CVE-2026-72819
HIGH 8.7
Grav — Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings vali…● PoC
2026-08-14
CVE-2026-72820
MEDIUM 6.9
Grav — Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive…● PoC
2026-08-14
CVE-2026-72821
MEDIUM 5.1
Grav — Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggl…
2026-08-14
CVE-2026-72822
CRITICAL 9.3
Grav — The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope…● PoC
2026-08-14
CVE-2026-72823
MEDIUM 5.3
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoContro…
2026-08-14
CVE-2026-72824
CRITICAL 9.3
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesContr…● PoC
2026-08-14
CVE-2026-72825
HIGH 7.2
Grav — The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twi…● PoC
2026-08-14
CVE-2026-72826
CRITICAL 9.3
Grav — The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key …
2026-08-14
CVE-2026-72827
HIGH 8.7
Grav — Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that…● PoC
2026-08-14
CVE-2026-72828
HIGH 8.6
Grav — Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsCont…
2026-08-14
CVE-2026-72829
CRITICAL 9.3
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersContr…● PoC
2026-08-14
CVE-2026-72830
CRITICAL 9.3
Grav — Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gate…● PoC
2026-08-14
CVE-2026-72831
HIGH 8.7
Grav — The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerabi…● PoC
2026-08-14
CVE-2026-72832
MEDIUM 5.1
Grav — Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::d…● PoC
2026-08-14
CVE-2026-72833
HIGH 8.7
Grav — The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation v…
2026-08-14
CVE-2026-69087
HIGH 7.1
Grav Plugin Form — The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v…● PoC
2026-08-03
CVE-2026-69088
HIGH 8.6
Grav — Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in…● PoC
2026-08-03
CVE-2026-69089
HIGH 8.7
Grav — Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsaniti…● PoC
2026-08-03
CVE-2026-66400
MEDIUM 6.3
Grav — Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStor…● PoC
2026-07-29
CVE-2026-65608
HIGH 8.7
Grav — Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicD…● PoC
2026-07-23
CVE-2026-65895
HIGH 8.2
Grav — Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration…● PoC
2026-07-23
CVE-2026-65896
HIGH 7.1
Grav — Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug f…● PoC
2026-07-23
CVE-2026-65897
HIGH 8.7
Grav — Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), a…● PoC
2026-07-23
CVE-2026-65603
HIGH 8.7
Grav — The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authen…● PoC
2026-07-22
CVE-2026-64628
MEDIUM 5.1
Grav — Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS d…● PoC
2026-07-21
CVE-2026-65007
HIGH 8.7
Grav — The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocati…● PoC
2026-07-21
CVE-2026-65008
CRITICAL 9.3
Grav — Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system…● PoC
2026-07-21
CVE-2026-62230
HIGH 8.7
Grav — Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blockin…● PoC
2026-07-17
CVE-2026-62231
HIGH 8.6
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be c…● PoC
2026-07-17
CVE-2026-62232
CRITICAL 9.1
Grav — Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the rege…● PoC
2026-07-17
CVE-2026-62233
HIGH 8.7
Grav — grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa…
2026-07-17
CVE-2026-62234
HIGH 8.4
Grav — Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.…● PoC
2026-07-17
CVE-2026-62235
LOW 2.3
Grav — Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST A…
2026-07-17
CVE-2026-62236
LOW 2.3
Grav — grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regene…● PoC
2026-07-17
CVE-2026-62237
MEDIUM 6
Grav — Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace f…● PoC
2026-07-17
CVE-2026-62386
HIGH 8.2
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token=…● PoC
2026-07-17
CVE-2026-62387
HIGH 7.1
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its…● PoC
2026-07-17
CVE-2026-58655
HIGH 8.7
Grav — The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-…● PoC
2026-07-15
CVE-2026-61449
HIGH 7.1
Grav — Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound intr…● PoC
2026-07-15
CVE-2026-61451
CRITICAL 9.4
Grav — The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_b…● PoC
2026-07-15
CVE-2026-61452
MEDIUM 6.9
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerabi…● PoC
2026-07-15
CVE-2026-61453
MEDIUM 5.1
Grav — Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Secur…● PoC
2026-07-15
CVE-2026-61457
MEDIUM 5.3
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API …● PoC
2026-07-15
CVE-2026-61873
HIGH 7.2
Grav — Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename pa…● PoC
2026-07-15
CVE-2026-61454
HIGH 8.7
Grav — The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__…● PoC
2026-07-11
CVE-2026-53653
HIGH 8.7
Grav — Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to e…
2026-07-10
CVE-2026-55885
MEDIUM 6.8
Grav — Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can…● PoC
2026-07-10
CVE-2026-55890
MEDIUM 4.8
Grav — Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markd…● PoC
2026-07-10
CVE-2026-58492
CRITICAL 9.2
Grav — grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpol…
2026-07-10
CVE-2026-58493
MEDIUM 5.1
Grav — grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN stri…● PoC
2026-07-10
CVE-2026-59190
HIGH 8.7
Grav — grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages.…● PoC
2026-07-10
CVE-2026-59193
MEDIUM 6.9
Grav — Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill th…● PoC
2026-07-10
CVE-2026-61450
HIGH 7.1
Grav — Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone ab…● PoC
2026-07-10
CVE-2026-61455
HIGH 7.1
Grav — Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on u…● PoC
2026-07-10
CVE-2026-61456
MEDIUM 5.1
Grav — The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the PO…● PoC
2026-07-10