getgrav/grav
Packagist105 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting getgrav/gravpage 3 of 3
- CVE-2026-75834MEDIUMCVSS 5.4EG 5.4fixed in 2.0.142026-08-18
vulnerable: 0.8.0 ... 2.0.9 (348 versions)
Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byt…
- CVE-2026-75837CRITICALCVSS 9.1EG 9.1fixed in 2.0.142026-08-18
vulnerable: 0.8.0 ... 2.0.9 (348 versions)
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admi…
- CVE-2026-76839MEDIUMCVSS 6.5EG 6.5fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User obj…
- CVE-2026-76846HIGHCVSS 7.5EG 7.5fixed in 2.0.162026-08-25
vulnerable: 0.8.0 ... 2.0.9 (350 versions)
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig t…
- CVE-2026-86197MEDIUMCVSS 5.1EG 5.1fixed in 2.0.202026-09-05
vulnerable: 0.8.0 ... 2.0.9 (354 versions)
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by register…
Check whether getgrav/grav is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for getgrav/grav CVEs against the assets you own.
Book a Demo →