Records whose assigning authority named Getgrav as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92917Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_rgetgrav grav
CVE-2026-92916Grav through 2.0.21 Unauthenticated Information Disclosure via Clockworkgetgrav grav
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandboxgetgrav grav
CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Headergetgrav grav-plugin-api
CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flaggetgrav grav-plugin-api
CVE-2026-86194Grav Form Plugin before 9.1.22 Cross-Page Form Executiongetgrav grav-plugin-form
CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Supergetgrav grav-plugin-api
CVE-2026-85604Grav before 2.0.18 Remote Code Execution via sort filtergetgrav grav
CVE-2026-85603Grav Admin Plugin Path Traversal via Save As Language Codegetgrav grav
CVE-2026-85602Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypassgetgrav grav-plugin-form
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.jsgetgrav grav
CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via usernamegetgrav grav-plugin-admin2
CVE-2026-85599Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersgetgrav grav-plugin-shortcode-core
CVE-2026-85598Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pagesgetgrav grav
CVE-2026-80204Grav before 1.0.18 Authentication Bypass via Scoped API Keygetgrav grav
CVE-2026-80203Grav before 1.0.18 Authentication Bypass via Scoped API Keygetgrav grav
CVE-2026-76846Grav before 2.0.16 Information Disclosure via Twig Sandboxgetgrav grav
CVE-2026-76839Grav before 2.0.16 Information Disclosure via offsetGetgetgrav grav
CVE-2026-75837Grav before 2.0.14 Privilege Escalation via Group Access Fieldgetgrav grav
CVE-2026-75836Grav API Plugin before 1.0.14 Missing Authorizationgetgrav grav
CVE-2026-75835Grav API Plugin before 1.0.14 Missing Authorizationgetgrav grav
CVE-2026-75834Grav before 2.0.14 Stored XSS via Invalid UTF-8 Bytegetgrav grav
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypassgetgrav grav
CVE-2026-75832Grav API Plugin before 1.0.14 Authorization Bypassgetgrav grav
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URLgetgrav grav
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopygetgrav grav
CVE-2026-75829grav-plugin-api before 1.0.15 Twig SSTI via translate endpointgetgrav grav
CVE-2026-75828Grav before 2.0.15 Stored XSS via detectXss() Quote Bypassgetgrav grav
CVE-2026-75827Grav before 2.0.15 Arbitrary File Write via error_loggetgrav grav
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twiggetgrav grav
CVE-2026-75107Grav Form Plugin before 9.1.19 Stored XSS via Field Propertiesgetgrav grav
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVGgetgrav grav
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgetgrav grav
CVE-2026-72833Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keysgetgrav grav
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypassgetgrav grav
CVE-2026-72831Grav through 2.0.11 Authentication Bypass via Flex Objectsgetgrav grav
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgetgrav grav
CVE-2026-72829Grav before 1.0.13 API Key Scope Bypass via UsersControllergetgrav grav
CVE-2026-72828Grav before 1.0.13 API Key Scope Bypass via InvitationsControllergetgrav grav
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twiggetgrav grav
CVE-2026-72826Grav before 1.0.13 Scope Bypass via createApiKeygetgrav grav
CVE-2026-72825Grav before 1.0.13 API-key scope cap bypass via ReportsControllergetgrav grav
CVE-2026-72824Grav before 1.0.13 API Key Scope Bypass via PagesControllergetgrav grav
CVE-2026-72823Grav before 1.0.13 API-key scope cap bypass via DemoControllergetgrav grav
CVE-2026-72822Grav before 1.0.13 Authentication Bypass via disable2fagetgrav grav
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Togglegetgrav grav
CVE-2026-72820Grav 2.0.11 Path Traversal via Backup Profile Configurationgetgrav grav
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgetgrav grav
CVE-2026-72702Grav CMS before 2.0.16 Origin Validation Bypass via Referergetgrav grav
CVE-2026-72701Grav CMS before 2.0.16 Timing Attack via verifyNoncegetgrav grav
CVE-2026-72700Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparisongetgrav grav
CVE-2026-72699Grav Login Plugin before 3.9.1 Email Enumeration via Registrationgetgrav grav-plugin-login
CVE-2026-72698Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypassgetgrav grav
CVE-2026-72697Grav CMS before 2.0.16 Path Traversal via media_directorygetgrav grav
CVE-2026-72696Grav CMS before 2.0.16 Symlink Following via createLockFilegetgrav grav
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFilegetgrav grav
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgetgrav grav
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgetgrav grav
CVE-2026-69087Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twiggetgrav grav-plugin-form
CVE-2026-66400Grav Login Plugin before 3.8.13 Insufficient Session Expirationgetgrav grav
CVE-2026-65897Grav API Plugin 1.0.9 Privilege Escalation via Invitations groupsgetgrav grav
CVE-2026-65896Grav API Plugin before 1.0.10 Path Traversal via movegetgrav grav
CVE-2026-65895Grav API Plugin before 1.0.10 Broken Access Controlgetgrav grav
CVE-2026-65608Grav before 2.0.9 Remote Code Execution via FlexDirectorygetgrav grav
CVE-2026-65603Grav Login Plugin 3.8.11 Privilege Escalation via Profile Updategetgrav grav
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagetgrav grav
CVE-2026-65007Grav before 1.0.8 Missing Authorization on API Key Generationgetgrav grav
CVE-2026-64852Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any accountgetgrav grav-plugin-api
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()getgrav grav
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlersgetgrav grav
CVE-2026-63408Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parametergetgrav grav-plugin-api
CVE-2026-63407Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responsesgetgrav grav-plugin-api
CVE-2026-62673Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsgetgrav grav
CVE-2026-62672Grav: Authenticated ReDoS via regex_replace in Twig Sandboxgetgrav grav
CVE-2026-62671CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on…getgrav grav-plugin-login
CVE-2026-62670Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less…getgrav grav-plugin-flex-objects
CVE-2026-62669Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challengegetgrav grav-plugin-login
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocolsgetgrav grav-plugin-api
CVE-2026-62667Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACLgetgrav grav-plugin-api
CVE-2026-62666Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190)…getgrav grav-plugin-api
CVE-2026-62387Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugingetgrav grav
CVE-2026-62386Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parametergetgrav grav
CVE-2026-62237Grav < 2.0.4 ReDoS via regex_replace in Sandboxgetgrav grav
CVE-2026-62236grav-plugin-login < 3.8.11 CSRF via regenerate2FASecretgetgrav grav
CVE-2026-62235Grav Flex-Objects < 1.4.3 Authorization Bypass via APIgetgrav grav
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocolsgetgrav grav
CVE-2026-62233grav-plugin-api < 1.0.6 Privilege Escalation via createApiKeygetgrav grav
CVE-2026-62232Grav < 2.0.4 2FA Bypass via Secret Regenerationgetgrav grav
CVE-2026-62231Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticatorgetgrav grav
CVE-2026-62230Grav < 2.0.4 File Access Bypass via Case Variationgetgrav grav
CVE-2026-61873Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filenamegetgrav grav
180 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.