getgrav/grav
Packagist105 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting getgrav/gravpage 2 of 3
- CVE-2025-66843MEDIUMCVSS 5.4EG 5.42025-12-15
vulnerable: 0.8.0 ... 1.7.9 (285 versions)
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editab…
- CVE-2025-66844CRITICALCVSS 9.1EG 9.12025-12-15
vulnerable: 0.8.0 ... 1.7.9 (285 versions)
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
- CVE-2026-42607CRITICALCVSS 9.1EG 9.1fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially crafted ZIP file through the "Direct Install" tool. While the s…
- CVE-2026-42608CRITICALCVSS 9.1EG 9.1fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST requests), an unauthenticated attacker…
- CVE-2026-42609HIGHCVSS 8.1EG 8.1fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existing accounts, including the primary admin…
- CVE-2026-42610MEDIUMCVSS 6.5EG 6.5fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing the grav['accounts'] service. Attacker c…
- CVE-2026-42611HIGHCVSS 8.9EG 8.9fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated to dump the entire system information ava…
- CVE-2026-42612HIGHCVSS 8.5EG 8.5fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue arises from a blacklist bypass in the de…
- CVE-2026-42613CRITICALCVSS 9.4EG 9.4fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and access fields from the registration POST data without server-side validation. When registrati…
- CVE-2026-42841MEDIUMCVSS 4.8EG 4.8fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML through Grav's Markdown media action syntax.…
- CVE-2026-42842MEDIUMCVSS 5.4EG 5.4fixed in 2.0.0-beta.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered …
- CVE-2026-42844HIGHCVSS 8.8EG 8.8fixed in 2.0.0-beta.42026-05-12
vulnerable: 0.8.0 ... 2.0.0-beta.3 (323 versions)
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/accounts/, then log in as the newly created …
- CVE-2026-44737MEDIUMCVSS 6.2EG 6.2fixed in 1.7.49.52026-05-11
vulnerable: 0.8.0 ... 1.7.9 (284 versions)
grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user …
- CVE-2026-44738HIGHCVSS 7.7EG 7.7fixed in 2.0.0-rc.22026-05-11
vulnerable: 0.8.0 ... 2.0.0-rc.1 (325 versions)
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all…
- CVE-2026-53653HIGHCVSS 8.7EG 8.7fixed in 2.0.0-rc.8 or 1.7.53, by version range2026-07-10
vulnerable: 0.8.0 ... 1.7.9 (287 versions)
Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as fo…
- CVE-2026-55885MEDIUMCVSS 6.8EG 6.8fixed in 1.7.532026-06-18
vulnerable: 0.8.0 ... 1.7.9 (287 versions)
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator pas…
- CVE-2026-55890MEDIUMCVSS 4.8EG 4.8fixed in 2.0.0-rc.92026-06-18
vulnerable: 0.8.0 ... 2.0.0-rc.8 (332 versions)
Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown…
- CVE-2026-56700CRITICALCVSS 9.8EG 9.8fixed in 2.0.0-beta.22026-07-01
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowe…
- CVE-2026-56701MEDIUMCVSS 6.5EG 6.5fixed in 2.0.0-beta.22026-06-23
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simplexml_load_string without disabling extern…
- CVE-2026-58657MEDIUMCVSS 4.8EG 4.8fixed in 2.0.02026-07-08
vulnerable: 2.0.0-rc.10, 2.0.0-rc.9
Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action. Prior media hardening rejects direct ?style= payloads and unsafe attribute() fall…
- CVE-2026-59193MEDIUMCVSS 4.9EG 4.9fixed in 2.0.02026-07-10
vulnerable: 1.0.0 ... 2.0.0-rc.9 (281 versions)
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::ex…
- CVE-2026-61449MEDIUMCVSS 6.5EG 6.5fixed in 2.0.22026-07-15
vulnerable: 2.0.1
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']…
- CVE-2026-61450MEDIUMCVSS 6.5EG 6.5fixed in 2.0.22026-07-10
vulnerable: 0.8.0 ... 2.0.1 (336 versions)
Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redact…
- CVE-2026-61453MEDIUMCVSS 6.1EG 6.1fixed in 2.0.12026-07-15
vulnerable: 2.0.0
Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_…
- CVE-2026-61455MEDIUMCVSS 6.5EG 6.5fixed in 2.0.12026-07-10
vulnerable: 0.8.0 ... 2.0.0-rc.9 (335 versions)
Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk s…
- CVE-2026-61690MEDIUMCVSS 6.5EG 6.5fixed in 2.0.12026-08-19
vulnerable: 0.8.0 ... 2.0.0-rc.9 (335 versions)
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file…
- CVE-2026-61842MEDIUMCVSS 6.5EG 6.5fixed in 2.0.22026-08-19
vulnerable: 0.8.0 ... 2.0.1 (336 versions)
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that ob…
- CVE-2026-62230HIGHCVSS 7.5EG 7.5fixed in 2.0.42026-07-17
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case…
- CVE-2026-62232HIGHCVSS 7.4EG 7.4fixed in 2.0.42026-07-17
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know …
- CVE-2026-62237MEDIUMCVSS 6.5EG 6.5fixed in 2.0.42026-07-17
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.…
- CVE-2026-62669HIGHCVSS 7.4EG 7.4fixed in 2.0.42026-08-19
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. Aft…
- CVE-2026-62672MEDIUMCVSS 6.0EG 6.0fixed in 2.0.42026-08-19
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). When…
- CVE-2026-62673HIGHCVSS 8.2EG 8.2fixed in 2.0.42026-08-19
vulnerable: 0.8.0 ... 2.0.3 (338 versions)
Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a …
- CVE-2026-64850HIGHCVSS 8.7EG 8.7fixed in 2.0.72026-08-19
vulnerable: 0.8.0 ... 2.0.6 (341 versions)
Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dange…
- CVE-2026-65008CRITICALCVSS 9.8EG 9.8fixed in 2.0.72026-07-21
vulnerable: 0.8.0 ... 2.0.6 (341 versions)
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_a…
- CVE-2026-65608HIGHCVSS 8.8EG 8.8fixed in 2.0.92026-07-23
vulnerable: 1.7.0 ... 2.0.8 (124 versions)
Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only…
- CVE-2026-69088HIGHCVSS 8.1EG 8.1fixed in 2.0.112026-08-03
vulnerable: 2.0.10, 2.0.7, 2.0.8, 2.0.9
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist to string…
- CVE-2026-69089HIGHCVSS 7.5EG 7.5fixed in 2.0.112026-08-03
vulnerable: 2.0.10
Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because the file:// scheme bra…
- CVE-2026-72695HIGHCVSS 8.1EG 8.1fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequen…
- CVE-2026-72697MEDIUMCVSS 6.5EG 6.5fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers wit…
- CVE-2026-72698MEDIUMCVSS 6.5EG 6.5fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configur…
- CVE-2026-72701LOWCVSS 3.7EG 3.7fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing di…
- CVE-2026-72702MEDIUMCVSS 5.4EG 5.4fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no tr…
- CVE-2026-72819HIGHCVSS 8.8EG 8.8fixed in 2.0.132026-08-14
vulnerable: 0.8.0 ... 2.0.9 (347 versions)
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypas…
- CVE-2026-72832MEDIUMCVSS 5.4EG 5.4fixed in 2.0.132026-08-14
vulnerable: 1.5.10 ... 2.0.9 (211 versions)
Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which can…
- CVE-2026-7317MEDIUMCVSS 5.0EG 5.0fixed in 2.0.0-beta.22026-04-28
vulnerable: 0.8.0 ... 2.0.0-beta.1 (321 versions)
A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-beta.1. Affected by this vulnerability is the function FileCache::doGet of the file system/src/Grav/Framework/Cache/Adapter/FileCache.php of the component Cache Value Handler. The …
- CVE-2026-74907MEDIUMCVSS 5.9EG 5.9fixed in 2.0.152026-08-18
vulnerable: 0.8.0 ... 2.0.9 (349 versions)
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling directo…
- CVE-2026-75827HIGHCVSS 8.8EG 8.8fixed in 2.0.152026-08-18
vulnerable: 0.8.0 ... 2.0.9 (349 versions)
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access …
- CVE-2026-75828HIGHCVSS 8.7EG 8.7fixed in 2.0.152026-08-18
vulnerable: 0.8.0 ... 2.0.9 (349 versions)
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like one…
- CVE-2026-75831HIGHCVSS 7.6EG 7.6fixed in 2.0.152026-08-18
vulnerable: 0.8.0 ... 2.0.9 (349 versions)
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowi…
Check whether getgrav/grav is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for getgrav/grav CVEs against the assets you own.
Book a Demo →