Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-66294
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authentic…
Grav
1.8.0+
MEDIUM 6.1
CVE-2025-63593
Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS).
Grav
No fix yet
HIGH 8.1
CVE-2025-50286EPSS 9%
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direc…
Grav
No fix yet
HIGH 8.8
CVE-2025-46198
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of …
Grav
after 1.7.48
CRITICAL 9.8
CVE-2025-46199
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
Grav
after 1.7.48
MEDIUM 6.1
CVE-2024-35498
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Grav
No fix yet
CRITICAL 9.9
CVE-2024-34082
Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twi…
Grav
1.7.46+
HIGH 8.8
CVE-2024-28118
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra…
Grav
1.7.45+
HIGH 8.8
CVE-2024-28119
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra…
Grav
1.7.45+
HIGH 8.8
CVE-2024-27921EPSS 61%
Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior …
Grav
1.7.45+
HIGH 8.8
CVE-2024-28116EPSS 6%
Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI…
Grav
1.7.45+
HIGH 8.8
CVE-2024-28117
Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger…
Grav
1.7.45+
HIGH 8.8
CVE-2024-27923
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …
Grav
1.7.43+
MEDIUM 5.4
CVE-2023-31506
A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts…
Grav
after 1.7.44
MEDIUM 6.1
CVE-2023-49146
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Dom Sanitizer
1.0.7+
HIGH 8.8
CVE-2023-37897
Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu…
Grav
Patch available
HIGH 7.2
CVE-2023-34253
Grav is a flat-file content management system. Prior to version 1.7.42, the denylist introduced in commit 9d6a2d to prevent dangerous functions from …
Grav
1.7.42+
HIGH 7.2
CVE-2023-34448
Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i…
Grav
1.7.42+
MEDIUM 6.1
CVE-2023-34452
Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vu…
Grav
after 1.7.42
HIGH 7.2
CVE-2023-34251
Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is po…
Grav
1.7.42+
HIGH 7.2
CVE-2023-34252
Grav is a flat-file content management system. Prior to version 1.7.42, there is a logic flaw in the `GravExtension.filterFilter()` function whereby …
Grav
1.7.42+
HIGH 7.2
CVE-2022-2073EPSS 10%
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
Grav
1.7.34+
MEDIUM 5.4
CVE-2022-1173
stored xss in GitHub repository getgrav/grav prior to 1.7.33.
Grav
1.7.33+
MEDIUM 5.4
CVE-2022-0970
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
Grav
1.7.31+
MEDIUM 5.4
CVE-2022-0268
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
Grav
1.7.28+
MEDIUM 5.4
CVE-2021-3920
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Grav Plugin Admin
1.10.25+
HIGH 7.5
CVE-2021-3924
grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Grav
after 1.7.24
MEDIUM 5.4
CVE-2021-3904
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Grav
1.7.24+
MEDIUM 5.4
CVE-2021-3799
grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
Grav Plugin Admin
1.10.20+
MEDIUM 5.3
CVE-2021-3818
grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
Grav
1.7.22+