Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2021-29439 The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.logi… Grav Admin 1.10.11+ Fix from $1,9502021-04-13 HIGH 7.2 CVE-2021-29440EPSS 31% Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or… Grav 1.7.11+ Fix from $1,9502021-04-13 CRITICAL 9.8 CVE-2021-21425EPSS 81% Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an una… Grav Plugin Admin 1.10.8+ Fix from $2,3002021-04-07 HIGH 8.8 CVE-2020-29553 The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (… Grav Cms after 1.6.31 Fix from $1,9502021-03-15 HIGH 8.1 CVE-2020-29555 The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by… Grav Cms 1.7.0+ Fix from $1,9502021-03-15 MEDIUM 5.5 CVE-2020-29556 The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by e… Grav Cms 1.7.0+ Fix from $1,6002021-03-15 MEDIUM 6.1 CVE-2020-11529EPSS 11% Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x. Grav after 1.6.31 Fix from $1,6002020-04-04 MEDIUM 6.1 CVE-2019-16126 Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images. Grav Cms after 1.6.15 Fix from $1,6002019-09-09 MEDIUM 6.1 CVE-2018-5233 Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary… Grav Cms 1.3.0+ Fix from $1,6002018-03-19