Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grav Admin HIGH 7.2
CVE-2021-29439

The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.logi…

Fix: 1.10.11+
Fix from $1,950 2021-04-13
Grav HIGH 7.2
CVE-2021-29440EPSS 31%

Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or…

Fix: 1.7.11+
Fix from $1,950 2021-04-13
Grav Plugin Admin CRITICAL 9.8
CVE-2021-21425EPSS 81%

Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an una…

Fix: 1.10.8+
Fix from $2,300 2021-04-07
Grav Cms HIGH 8.8
CVE-2020-29553

The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (…

Fix: after 1.6.31
Fix from $1,950 2021-03-15
Grav Cms HIGH 8.1
CVE-2020-29555

The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by…

Fix: 1.7.0+
Fix from $1,950 2021-03-15
Grav Cms MEDIUM 5.5
CVE-2020-29556

The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by e…

Fix: 1.7.0+
Fix from $1,600 2021-03-15
Grav MEDIUM 6.1
CVE-2020-11529EPSS 11%

Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

Fix: after 1.6.31
Fix from $1,600 2020-04-04
Grav Cms MEDIUM 6.1
CVE-2019-16126

Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.

Fix: after 1.6.15
Fix from $1,600 2019-09-09
Grav Cms MEDIUM 6.1
CVE-2018-5233

Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary…

Fix: 1.3.0+
Fix from $1,600 2018-03-19