Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grav HIGH 8.8
CVE-2025-66294

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic…

Fix: 1.8.0+
Fix from $1,950 2025-12-01
Grav MEDIUM 6.1
CVE-2025-63593

Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2025-11-03
Grav HIGH 8.1
CVE-2025-50286EPSS 9%

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direc…

No fix yet
Fix from $1,950 2025-08-06
Grav HIGH 8.8
CVE-2025-46198

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of …

Fix: after 1.7.48
Fix from $1,950 2025-07-25
Grav CRITICAL 9.8
CVE-2025-46199

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

Fix: after 1.7.48
Fix from $2,300 2025-07-25
Grav MEDIUM 6.1
CVE-2024-35498

A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

No fix yet
Fix from $1,600 2025-01-06
Grav CRITICAL 9.9
CVE-2024-34082

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twi…

Fix: 1.7.46+
Fix from $2,300 2024-05-15
Grav HIGH 8.8
CVE-2024-28118

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28119

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-27921EPSS 61%

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior …

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28116EPSS 6%

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-28117

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger…

Fix: 1.7.45+
Fix from $1,950 2024-03-21
Grav HIGH 8.8
CVE-2024-27923

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …

Fix: 1.7.43+
Fix from $1,950 2024-03-21
Grav MEDIUM 5.4
CVE-2023-31506

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts…

Fix: after 1.7.44
Fix from $1,600 2024-02-09
Dom Sanitizer MEDIUM 6.1
CVE-2023-49146

DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.

Fix: 1.0.7+
Fix from $1,600 2023-11-22
Grav HIGH 8.8
CVE-2023-37897

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu…

Patch available
Fix from $1,950 2023-07-18
Grav HIGH 7.2
CVE-2023-34253

Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from …

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2023-34448

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i…

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav MEDIUM 6.1
CVE-2023-34452

Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vu…

Fix: after 1.7.42
Fix from $1,600 2023-06-14
Grav HIGH 7.2
CVE-2023-34251

Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po…

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2023-34252

Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby …

Fix: 1.7.42+
Fix from $1,950 2023-06-14
Grav HIGH 7.2
CVE-2022-2073EPSS 10%

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

Fix: 1.7.34+
Fix from $1,950 2022-06-29
Grav MEDIUM 5.4
CVE-2022-1173

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

Fix: 1.7.33+
Fix from $1,600 2022-04-26
Grav MEDIUM 5.4
CVE-2022-0970

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

Fix: 1.7.31+
Fix from $1,600 2022-03-15
Grav MEDIUM 5.4
CVE-2022-0268

Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.

Fix: 1.7.28+
Fix from $1,600 2022-01-25
Grav Plugin Admin MEDIUM 5.4
CVE-2021-3920

grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 1.10.25+
Fix from $1,600 2021-11-19
Grav HIGH 7.5
CVE-2021-3924

grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Fix: after 1.7.24
Fix from $1,950 2021-11-05
Grav MEDIUM 5.4
CVE-2021-3904

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fix: 1.7.24+
Fix from $1,600 2021-10-27
Grav Plugin Admin MEDIUM 5.4
CVE-2021-3799

grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

Fix: 1.10.20+
Fix from $1,600 2021-09-27
Grav MEDIUM 5.3
CVE-2021-3818

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

Fix: 1.7.22+
Fix from $1,600 2021-09-27