Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-37256 Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users wit… Grav 1.6.30+ Fix from $1,6002026-06-25 HIGH 8.8 CVE-2026-42844 Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl… Grav No fix yet Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-42843 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system mana… Grav Plugin Api No fix yet Fix from $1,9502026-05-11 HIGH 7.7 CVE-2026-44738 Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray… Grav 2.0.0+ Fix from $1,9502026-05-11 HIGH 8.9 CVE-2026-42611 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection … Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 5.4 CVE-2026-42612 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level ac… Grav after 1.8.0 Fix from $1,6002026-05-11 CRITICAL 9.1 CVE-2026-42608 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin… Grav 2.0.0+ Fix from $2,3002026-05-11 HIGH 8.1 CVE-2026-42609 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o… Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-42610 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass th… Grav after 1.8.0 Fix from $1,6002026-05-11 HIGH 7.6 CVE-2026-29924 Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager p… Grav 1.8.0+ Fix from $1,9502026-03-30 CRITICAL 9.8 CVE-2021-47812 GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro… Grav Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.1 CVE-2025-66844 In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the con… Grav 1.7.49.5+ Fix from $2,3002025-12-15 MEDIUM 5.4 CVE-2025-66843 grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged… Grav 1.7.49.5+ Fix from $1,6002025-12-15 MEDIUM 6.1 CVE-2025-65186 Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. T… Grav No fix yet Fix from $1,6002025-12-02 MEDIUM 5.4 CVE-2025-66310 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 MEDIUM 5.4 CVE-2025-66311 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 MEDIUM 5.4 CVE-2025-66312 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 HIGH 7.2 CVE-2025-66304 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view … Grav 1.8.0+ Fix from $1,9502025-12-01 MEDIUM 6.5 CVE-2025-66306 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Pa… Grav 1.8.0+ Fix from $1,6002025-12-01 MEDIUM 6.1 CVE-2025-66309 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 MEDIUM 5.4 CVE-2025-66308 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 MEDIUM 5.3 CVE-2025-66307 This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.… Grav Plugin Admin after 1.10.50 Fix from $1,6002025-12-01 CRITICAL 9.6 CVE-2025-66301 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /… Grav 1.8.0+ Fix from $2,3002025-12-01 HIGH 8.8 CVE-2025-66299 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenti… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.5 CVE-2025-66300 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 7.5 CVE-2025-66298 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including pl… Grav 1.8.0+ Fix from $1,9502025-12-01 MEDIUM 6.8 CVE-2025-66302 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated att… Grav 1.8.0+ Fix from $1,6002025-12-01 HIGH 8.8 CVE-2025-66295 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and su… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-66296 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of u… Grav 1.8.0+ Fix from $1,9502025-12-01 HIGH 8.8 CVE-2025-66297 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can ena… Grav 1.8.0+ Fix from $1,9502025-12-01