getgrav/grav
Packagist105 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting getgrav/gravpage 1 of 3
- CVE-2018-5233MEDIUMCVSS 6.1EG 6.1fixed in 1.3.02018-03-19
vulnerable: 0.8.0 ... 1.3.0-rc.5 (106 versions)
Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.
- CVE-2019-16126MEDIUMCVSS 6.1EG 6.1fixed in 1.7.0-beta.82019-09-09
vulnerable: 0.8.0 ... 1.7.0-beta.7 (196 versions)
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
- CVE-2020-11529MEDIUMCVSS 6.1EG 6.1fixed in 1.6.232020-04-04
vulnerable: 0.8.0 ... 1.6.9 (180 versions)
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
- CVE-2020-29553HIGHCVSS 8.8EG 8.8fixed in 1.6.302021-03-15
vulnerable: 0.8.0 ... 1.6.9 (187 versions)
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).
- CVE-2020-29555HIGHCVSS 8.1EG 8.1fixed in 1.6.302021-03-15
vulnerable: 0.8.0 ... 1.6.9 (187 versions)
The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an un…
- CVE-2020-29556MEDIUMCVSS 5.5EG 5.5fixed in 1.6.302021-03-15
vulnerable: 0.8.0 ... 1.6.9 (187 versions)
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unau…
- CVE-2020-37256MEDIUMCVSS 5.4EG 5.4fixed in 1.6.302026-06-25
vulnerable: 0.8.0 ... 1.6.9 (187 versions)
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and ins…
- CVE-2021-29440HIGHCVSS 8.4EG 8.4fixed in 1.7.112021-04-13
vulnerable: 0.8.0 ... 1.7.9 (229 versions)
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arb…
- CVE-2021-3818MEDIUMCVSS 5.3EG 5.3fixed in 1.7.212021-09-27
vulnerable: 0.8.0 ... 1.7.9 (238 versions)
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
- CVE-2021-3904MEDIUMCVSS 5.4EG 5.4fixed in 1.7.242021-10-27
vulnerable: 0.8.0 ... 1.7.9 (241 versions)
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2021-3924HIGHCVSS 7.5EG 8.82021-11-05
vulnerable: 0.8.0 ... 1.7.9 (242 versions)
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CVE-2022-0268MEDIUMCVSS 5.4EG 5.4fixed in 1.7.282022-01-25
vulnerable: 0.8.0 ... 1.7.9 (247 versions)
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
- CVE-2022-0743MEDIUMCVSS 4.6EG 4.6fixed in 1.7.312022-02-28
vulnerable: 0.8.0 ... 1.7.9 (251 versions)
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
- CVE-2022-0970MEDIUMCVSS 5.4EG 5.4fixed in 1.7.312022-03-15
vulnerable: 0.8.0 ... 1.7.9 (251 versions)
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
- CVE-2022-1173MEDIUMCVSS 5.4EG 5.4fixed in 1.7.332022-04-26
vulnerable: 0.8.0 ... 1.7.9 (253 versions)
stored xss in GitHub repository getgrav/grav prior to 1.7.33.
- CVE-2022-2073HIGHCVSS 7.2EG 7.2fixed in 1.7.342022-06-29
vulnerable: 0.8.0 ... 1.7.9 (254 versions)
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
- CVE-2023-31506MEDIUMCVSS 5.4EG 5.42024-02-09
vulnerable: 0.8.0 ... 2.0.9 (360 versions)
A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.
- CVE-2023-34251CRITICALCVSS 9.9EG 9.9fixed in 1.7.422023-06-14
vulnerable: 0.8.0 ... 1.7.9 (269 versions)
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page edi…
- CVE-2023-34252HIGHCVSS 8.8EG 8.8fixed in 1.7.422023-06-14
vulnerable: 0.8.0 ... 1.7.9 (269 versions)
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby validation against a denylist of unsafe functions is only performed when the argument pass…
- CVE-2023-34253HIGHCVSS 8.8EG 8.8fixed in 1.7.422023-06-14
vulnerable: 0.8.0 ... 1.7.9 (269 versions)
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from being executed via injection of malicious templates was insufficient and could be easily s…
- CVE-2023-34448HIGHCVSS 8.8EG 8.8fixed in 1.7.422023-06-14
vulnerable: 0.8.0 ... 1.7.9 (269 versions)
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions …
- CVE-2023-37897HIGHCVSS 7.2EG 7.2fixed in 1.7.42.22023-07-18
vulnerable: 0.8.0 ... 1.7.9 (271 versions)
Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1…
- CVE-2024-27921HIGHCVSS 8.8EG 8.9fixed in 1.7.452024-03-21
vulnerable: 0.8.0 ... 1.7.9 (275 versions)
Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .jso…
- CVE-2024-27923HIGHCVSS 8.8EG 8.8fixed in 1.7.432024-03-21
vulnerable: 0.8.0 ... 1.7.9 (273 versions)
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code ex…
- CVE-2024-28116HIGHCVSS 8.8EG 8.8fixed in 1.7.452024-03-21
vulnerable: 0.8.0 ... 1.7.9 (275 versions)
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbi…
- CVE-2024-28117HIGHCVSS 8.8EG 8.8fixed in 1.7.452024-03-21
vulnerable: 0.8.0 ... 1.7.9 (275 versions)
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_m…
- CVE-2024-28118HIGHCVSS 8.8EG 8.8fixed in 1.7.452024-03-21
vulnerable: 0.8.0 ... 1.7.9 (275 versions)
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a pr…
- CVE-2024-28119HIGHCVSS 8.8EG 8.8fixed in 1.7.452024-03-21
vulnerable: 0.8.0 ... 1.7.9 (275 versions)
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Tw…
- CVE-2024-34082HIGHCVSS 8.5EG 8.5fixed in 1.7.462024-05-15
vulnerable: 0.8.0 ... 1.7.9 (276 versions)
Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file …
- CVE-2024-35498MEDIUMCVSS 6.1EG 6.12025-01-06
vulnerable: 0.8.0 ... 1.7.9 (276 versions)
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- CVE-2025-65186MEDIUMCVSS 6.1EG 6.12025-12-02
vulnerable: 0.8.0 ... 1.7.9 (280 versions)
Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execut…
- CVE-2025-66294HIGHCVSS 8.8EG 8.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, un…
- CVE-2025-66295HIGHCVSS 8.8EG 8.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat), …
- CVE-2025-66296HIGHCVSS 8.8EG 8.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…
- CVE-2025-66297HIGHCVSS 8.8EG 8.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the …
- CVE-2025-66298HIGHCVSS 7.5EG 7.5fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Tem…
- CVE-2025-66299HIGHCVSS 8.8EG 8.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassi…
- CVE-2025-66300HIGHCVSS 8.5EG 8.5fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), whi…
- CVE-2025-66301CRITICALCVSS 9.6EG 9.6fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the fo…
- CVE-2025-66302MEDIUMCVSS 6.8EG 6.8fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server fil…
- CVE-2025-66303MEDIUMCVSS 4.9EG 4.9fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize inp…
- CVE-2025-66304HIGHCVSS 7.2EG 7.2fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially …
- CVE-2025-66305MEDIUMCVSS 4.9EG 4.9fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel (/admin/config/system). Specifically, the Supported paramete…
- CVE-2025-66306MEDIUMCVSS 6.5EG 6.5fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. …
- CVE-2025-66307MEDIUMCVSS 5.3EG 5.3fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Fo…
- CVE-2025-66308MEDIUMCVSS 5.4EG 5.4fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admi…
- CVE-2025-66309MEDIUMCVSS 6.1EG 6.1fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /a…
- CVE-2025-66310MEDIUMCVSS 5.4EG 5.4fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admi…
- CVE-2025-66311MEDIUMCVSS 5.4EG 5.4fixed in 1.11.0-beta.12025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (320 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admi…
- CVE-2025-66312MEDIUMCVSS 5.4EG 5.4fixed in 1.8.0-beta.272025-12-01
vulnerable: 0.8.0 ... 1.8.0-beta.9 (317 versions)
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admi…
Check whether getgrav/grav is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for getgrav/grav CVEs against the assets you own.
Book a Demo →