getgrav Grav
14 known vulnerabilities in getgrav Grav, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100671 CVSS 8.6 high Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been…
- CVE-2026-100670 CVSS 8.7 high Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated…
- CVE-2026-100669 CVSS 8.7 high Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In…
- CVE-2026-100668 CVSS 7.1 high Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox…
- CVE-2026-100667 CVSS 6.9 medium grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed…
- CVE-2026-92917 CVSS 8.7 high Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters…
- CVE-2026-92916 CVSS 8.7 high Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled…
- CVE-2025-64059 CVSS 1.8 low Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because…
- CVE-2026-86197 CVSS 5.1 medium Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on…
- CVE-2026-85604 CVSS 8.7 high Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc…
- CVE-2026-85603 CVSS 7.1 high Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the…
- CVE-2026-85601 CVSS 5.1 medium Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in…
- CVE-2026-85598 CVSS 5.1 medium Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store…
- CVE-2026-42608 CVSS 8.8 high Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By…