Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grav MEDIUM 5.4
CVE-2020-37256

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users wit…

Fix: 1.6.30+
Fix from $1,600 2026-06-25
Grav HIGH 8.8
CVE-2026-42844

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl…

No fix yet
Fix from $1,950 2026-05-12
Grav Plugin Api HIGH 8.8
CVE-2026-42843

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system mana…

No fix yet
Fix from $1,950 2026-05-11
Grav HIGH 7.7
CVE-2026-44738

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray…

Fix: 2.0.0+
Fix from $1,950 2026-05-11
Grav HIGH 8.9
CVE-2026-42611

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection …

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Grav MEDIUM 5.4
CVE-2026-42612

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level ac…

Fix: after 1.8.0
Fix from $1,600 2026-05-11
Grav CRITICAL 9.1
CVE-2026-42608

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin…

Fix: 2.0.0+
Fix from $2,300 2026-05-11
Grav HIGH 8.1
CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o…

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Grav MEDIUM 6.5
CVE-2026-42610

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass th…

Fix: after 1.8.0
Fix from $1,600 2026-05-11
Grav HIGH 7.6
CVE-2026-29924

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager p…

Fix: 1.8.0+
Fix from $1,950 2026-03-30
Grav CRITICAL 9.8
CVE-2021-47812

GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro…

Mitigation only
Fix from $2,300 2026-01-16
Grav CRITICAL 9.1
CVE-2025-66844

In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con…

Fix: 1.7.49.5+
Fix from $2,300 2025-12-15
Grav MEDIUM 5.4
CVE-2025-66843

grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged…

Fix: 1.7.49.5+
Fix from $1,600 2025-12-15
Grav MEDIUM 6.1
CVE-2025-65186

Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. T…

No fix yet
Fix from $1,600 2025-12-02
Grav Plugin Admin MEDIUM 5.4
CVE-2025-66310

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav Plugin Admin MEDIUM 5.4
CVE-2025-66311

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav Plugin Admin MEDIUM 5.4
CVE-2025-66312

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav HIGH 7.2
CVE-2025-66304

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view …

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav MEDIUM 6.5
CVE-2025-66306

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Pa…

Fix: 1.8.0+
Fix from $1,600 2025-12-01
Grav Plugin Admin MEDIUM 6.1
CVE-2025-66309

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav Plugin Admin MEDIUM 5.4
CVE-2025-66308

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav Plugin Admin MEDIUM 5.3
CVE-2025-66307

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.…

Fix: after 1.10.50
Fix from $1,600 2025-12-01
Grav CRITICAL 9.6
CVE-2025-66301

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /…

Fix: 1.8.0+
Fix from $2,300 2025-12-01
Grav HIGH 8.8
CVE-2025-66299

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenti…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav HIGH 8.5
CVE-2025-66300

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav HIGH 7.5
CVE-2025-66298

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including pl…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav MEDIUM 6.8
CVE-2025-66302

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated att…

Fix: 1.8.0+
Fix from $1,600 2025-12-01
Grav HIGH 8.8
CVE-2025-66295

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and su…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav HIGH 8.8
CVE-2025-66296

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of u…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav HIGH 8.8
CVE-2025-66297

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can ena…

Fix: 1.8.0+
Fix from $1,950 2025-12-01