Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-66294 Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic… Grav 1.8.0+ Fix from $1,9502025-12-01 MEDIUM 6.1 CVE-2025-63593 Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS). Grav No fix yet Fix from $1,6002025-11-03 HIGH 8.1 CVE-2025-50286EPSS 9% A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direc… Grav No fix yet Fix from $1,9502025-08-06 HIGH 8.8 CVE-2025-46198 Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of … Grav after 1.7.48 Fix from $1,9502025-07-25 CRITICAL 9.8 CVE-2025-46199 Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields Grav after 1.7.48 Fix from $2,3002025-07-25 MEDIUM 6.1 CVE-2024-35498 A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. Grav No fix yet Fix from $1,6002025-01-06 CRITICAL 9.9 CVE-2024-34082 Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twi… Grav 1.7.46+ Fix from $2,3002024-05-15 HIGH 8.8 CVE-2024-28118 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28119 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-27921EPSS 61% Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior … Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28116EPSS 6% Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-28117 Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger… Grav 1.7.45+ Fix from $1,9502024-03-21 HIGH 8.8 CVE-2024-27923 Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient … Grav 1.7.43+ Fix from $1,9502024-03-21 MEDIUM 5.4 CVE-2023-31506 A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts… Grav after 1.7.44 Fix from $1,6002024-02-09 MEDIUM 6.1 CVE-2023-49146 DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions. Dom Sanitizer 1.0.7+ Fix from $1,6002023-11-22 HIGH 8.8 CVE-2023-37897 Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu… Grav Patch available Fix from $1,9502023-07-18 HIGH 7.2 CVE-2023-34253 Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from … Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2023-34448 Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i… Grav 1.7.42+ Fix from $1,9502023-06-14 MEDIUM 6.1 CVE-2023-34452 Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vu… Grav after 1.7.42 Fix from $1,6002023-06-14 HIGH 7.2 CVE-2023-34251 Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po… Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2023-34252 Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby … Grav 1.7.42+ Fix from $1,9502023-06-14 HIGH 7.2 CVE-2022-2073EPSS 10% Code Injection in GitHub repository getgrav/grav prior to 1.7.34. Grav 1.7.34+ Fix from $1,9502022-06-29 MEDIUM 5.4 CVE-2022-1173 stored xss in GitHub repository getgrav/grav prior to 1.7.33. Grav 1.7.33+ Fix from $1,6002022-04-26 MEDIUM 5.4 CVE-2022-0970 Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. Grav 1.7.31+ Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-0268 Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28. Grav 1.7.28+ Fix from $1,6002022-01-25 MEDIUM 5.4 CVE-2021-3920 grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Grav Plugin Admin 1.10.25+ Fix from $1,6002021-11-19 HIGH 7.5 CVE-2021-3924 grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Grav after 1.7.24 Fix from $1,9502021-11-05 MEDIUM 5.4 CVE-2021-3904 grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Grav 1.7.24+ Fix from $1,6002021-10-27 MEDIUM 5.4 CVE-2021-3799 grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames Grav Plugin Admin 1.10.20+ Fix from $1,6002021-09-27 MEDIUM 5.3 CVE-2021-3818 grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking Grav 1.7.22+ Fix from $1,6002021-09-27