vciy

CVEs we hold for Getgrav

Records whose assigning authority named Getgrav as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92917Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_rgetgrav grav
CVE-2026-92916Grav through 2.0.21 Unauthenticated Information Disclosure via Clockworkgetgrav grav
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandboxgetgrav grav
CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Headergetgrav grav-plugin-api
CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flaggetgrav grav-plugin-api
CVE-2026-86194Grav Form Plugin before 9.1.22 Cross-Page Form Executiongetgrav grav-plugin-form
CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Supergetgrav grav-plugin-api
CVE-2026-85604Grav before 2.0.18 Remote Code Execution via sort filtergetgrav grav
CVE-2026-85603Grav Admin Plugin Path Traversal via Save As Language Codegetgrav grav
CVE-2026-85602Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypassgetgrav grav-plugin-form
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.jsgetgrav grav
CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via usernamegetgrav grav-plugin-admin2
CVE-2026-85599Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersgetgrav grav-plugin-shortcode-core
CVE-2026-85598Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pagesgetgrav grav
CVE-2026-80204Grav before 1.0.18 Authentication Bypass via Scoped API Keygetgrav grav
CVE-2026-80203Grav before 1.0.18 Authentication Bypass via Scoped API Keygetgrav grav
CVE-2026-76846Grav before 2.0.16 Information Disclosure via Twig Sandboxgetgrav grav
CVE-2026-76839Grav before 2.0.16 Information Disclosure via offsetGetgetgrav grav
CVE-2026-75837Grav before 2.0.14 Privilege Escalation via Group Access Fieldgetgrav grav
CVE-2026-75836Grav API Plugin before 1.0.14 Missing Authorizationgetgrav grav
CVE-2026-75835Grav API Plugin before 1.0.14 Missing Authorizationgetgrav grav
CVE-2026-75834Grav before 2.0.14 Stored XSS via Invalid UTF-8 Bytegetgrav grav
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypassgetgrav grav
CVE-2026-75832Grav API Plugin before 1.0.14 Authorization Bypassgetgrav grav
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URLgetgrav grav
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopygetgrav grav
CVE-2026-75829grav-plugin-api before 1.0.15 Twig SSTI via translate endpointgetgrav grav
CVE-2026-75828Grav before 2.0.15 Stored XSS via detectXss() Quote Bypassgetgrav grav
CVE-2026-75827Grav before 2.0.15 Arbitrary File Write via error_loggetgrav grav
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twiggetgrav grav
CVE-2026-75107Grav Form Plugin before 9.1.19 Stored XSS via Field Propertiesgetgrav grav
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVGgetgrav grav
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.phpgetgrav grav
CVE-2026-72833Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keysgetgrav grav
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypassgetgrav grav
CVE-2026-72831Grav through 2.0.11 Authentication Bypass via Flex Objectsgetgrav grav
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypassgetgrav grav
CVE-2026-72829Grav before 1.0.13 API Key Scope Bypass via UsersControllergetgrav grav
CVE-2026-72828Grav before 1.0.13 API Key Scope Bypass via InvitationsControllergetgrav grav
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twiggetgrav grav
CVE-2026-72826Grav before 1.0.13 Scope Bypass via createApiKeygetgrav grav
CVE-2026-72825Grav before 1.0.13 API-key scope cap bypass via ReportsControllergetgrav grav
CVE-2026-72824Grav before 1.0.13 API Key Scope Bypass via PagesControllergetgrav grav
CVE-2026-72823Grav before 1.0.13 API-key scope cap bypass via DemoControllergetgrav grav
CVE-2026-72822Grav before 1.0.13 Authentication Bypass via disable2fagetgrav grav
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Togglegetgrav grav
CVE-2026-72820Grav 2.0.11 Path Traversal via Backup Profile Configurationgetgrav grav
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Uploadgetgrav grav
CVE-2026-72702Grav CMS before 2.0.16 Origin Validation Bypass via Referergetgrav grav
CVE-2026-72701Grav CMS before 2.0.16 Timing Attack via verifyNoncegetgrav grav
CVE-2026-72700Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparisongetgrav grav
CVE-2026-72699Grav Login Plugin before 3.9.1 Email Enumeration via Registrationgetgrav grav-plugin-login
CVE-2026-72698Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypassgetgrav grav
CVE-2026-72697Grav CMS before 2.0.16 Path Traversal via media_directorygetgrav grav
CVE-2026-72696Grav CMS before 2.0.16 Symlink Following via createLockFilegetgrav grav
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFilegetgrav grav
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermarkgetgrav grav
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprintgetgrav grav
CVE-2026-69087Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twiggetgrav grav-plugin-form
CVE-2026-66400Grav Login Plugin before 3.8.13 Insufficient Session Expirationgetgrav grav
CVE-2026-65897Grav API Plugin 1.0.9 Privilege Escalation via Invitations groupsgetgrav grav
CVE-2026-65896Grav API Plugin before 1.0.10 Path Traversal via movegetgrav grav
CVE-2026-65895Grav API Plugin before 1.0.10 Broken Access Controlgetgrav grav
CVE-2026-65608Grav before 2.0.9 Remote Code Execution via FlexDirectorygetgrav grav
CVE-2026-65603Grav Login Plugin 3.8.11 Privilege Escalation via Profile Updategetgrav grav
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicDatagetgrav grav
CVE-2026-65007Grav before 1.0.8 Missing Authorization on API Key Generationgetgrav grav
CVE-2026-64852Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any accountgetgrav grav-plugin-api
CVE-2026-64851Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlersgetgrav grav-plugin-shortcode-core
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()getgrav grav
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlersgetgrav grav
CVE-2026-63408Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parametergetgrav grav-plugin-api
CVE-2026-63407Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responsesgetgrav grav-plugin-api
CVE-2026-62673Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsgetgrav grav
CVE-2026-62672Grav: Authenticated ReDoS via regex_replace in Twig Sandboxgetgrav grav
CVE-2026-62671CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on…getgrav grav-plugin-login
CVE-2026-62670Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less…getgrav grav-plugin-flex-objects
CVE-2026-62669Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challengegetgrav grav-plugin-login
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocolsgetgrav grav-plugin-api
CVE-2026-62667Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACLgetgrav grav-plugin-api
CVE-2026-62666Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190)…getgrav grav-plugin-api
CVE-2026-62387Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugingetgrav grav
CVE-2026-62386Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parametergetgrav grav
CVE-2026-62237Grav < 2.0.4 ReDoS via regex_replace in Sandboxgetgrav grav
CVE-2026-62236grav-plugin-login < 3.8.11 CSRF via regenerate2FASecretgetgrav grav
CVE-2026-62235Grav Flex-Objects < 1.4.3 Authorization Bypass via APIgetgrav grav
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocolsgetgrav grav
CVE-2026-62233grav-plugin-api < 1.0.6 Privilege Escalation via createApiKeygetgrav grav
CVE-2026-62232Grav < 2.0.4 2FA Bypass via Secret Regenerationgetgrav grav
CVE-2026-62231Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticatorgetgrav grav
CVE-2026-62230Grav < 2.0.4 File Access Bypass via Case Variationgetgrav grav
CVE-2026-61873Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filenamegetgrav grav
CVE-2026-61842Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)getgrav grav
CVE-2026-61690Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limitsgetgrav grav
CVE-2026-61607Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizergetgrav grav-plugin-api
CVE-2026-61457Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypassgetgrav grav
CVE-2026-61456Grav before 1.0.3 Stored XSS via SVG Upload APIgetgrav grav
CVE-2026-61455Grav before 2.0.1 Decompression Bomb via ZipArchivergetgrav grav
CVE-2026-61454Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__getgrav grav
CVE-2026-61453Grav before 2.0.1 XSS via Twig String Concatenationgetgrav grav
CVE-2026-61452Grav before 2.0.4 Improper Session Invalidation JWT Access Tokensgetgrav grav
CVE-2026-61451Grav before 1.0.4 Password Reset Token Poisoning via admin_base_urlgetgrav grav
CVE-2026-61450Grav before 2.0.2 Config Exfiltration via offsetGet Filtergetgrav grav
CVE-2026-61449Grav before 2.0.2 Decompression Bomb via Forged ZIP Sizegetgrav grav
CVE-2026-59193Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()getgrav grav
CVE-2026-59190Grav Admin Plugin — IDOR Privilege Escalation via saveUser()getgrav grav
CVE-2026-58656Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parametergetgrav grav
CVE-2026-58655Grav Flex Objects - Server-Side Template Injection via Dynamic Titlesgetgrav grav
CVE-2026-58493grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Constructiongetgrav grav
CVE-2026-58492grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolationgetgrav grav
CVE-2026-56710Grav Login Plugin before 1.0.16 Privilege Escalation via Unlockgetgrav grav
CVE-2026-56709Grav before 3.9.2 Host Header Injection via sendInvitationEmailgetgrav grav
CVE-2026-56708Grav API Plugin before 1.0.16 SSRF via DNS Rebindinggetgrav grav
CVE-2026-56707Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcodegetgrav grav
CVE-2026-55890Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()getgrav grav
CVE-2026-55885Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secretsgetgrav grav
CVE-2026-53654Grav: Unauthenticated open redirect via login twofa_cancel _redirectgetgrav grav
CVE-2026-53653Grav: Unauthenticated denial of service via unbounded image derivative dimensionsgetgrav grav
CVE-2026-44738Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()getgrav grav
CVE-2026-44737grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter…getgrav grav-plugin-admin
CVE-2026-42845Grav: Anonymous Page Content Overwrite via Form File Upload filename Overridegetgrav grav-plugin-form
CVE-2026-42844Grav: Low-privileged API users can create super-admin accounts via blueprint-uploadgetgrav grav
CVE-2026-42843grav-plugin-api: Grav API Privilege Escalation to Super Admingetgrav grav-plugin-api
CVE-2026-42842grav-plugin-form: XSS via Taxonomy Field Values in Admin Panelgetgrav grav-plugin-form
CVE-2026-42841Grav: Stored XSS via Markdown media attribute() action in Grav CMSgetgrav grav
CVE-2026-42613Grav: Privilege Escalation via Missing Server-Side Validation of groups/accessgetgrav grav
CVE-2026-42612Grav: Publisher-Level Stored XSS via Unquoted Event Attributesgetgrav grav
CVE-2026-42611Grav: Stored XSS via Tag Injectiongetgrav grav
CVE-2026-42610Grav: Sensitive Information Disclosure via Accounts Service Bypassgetgrav grav
CVE-2026-42609Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logicgetgrav grav
CVE-2026-42608Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.getgrav grav
CVE-2026-42607Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Featuregetgrav grav
CVE-2025-66312Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter…getgrav grav
CVE-2025-66311Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parametersgetgrav grav
CVE-2025-66310Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]`…getgrav grav
CVE-2025-66309Grav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter…getgrav grav
CVE-2025-66308Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter…getgrav grav
CVE-2025-66307Grav Admin Plugin vulnerable to User Enumeration & Email Disclosuregetgrav grav
CVE-2025-66306Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panelgetgrav grav
CVE-2025-66305Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parametergetgrav grav
CVE-2025-66304Grav Exposes Password Hashes Leading to privilege escalationgetgrav grav
CVE-2025-66303Grav is vulnerable to a DOS on the admin panelgetgrav grav
CVE-2025-66302Grav vulnerable to Path Traversal allowing server files backupgetgrav grav
CVE-2025-66301Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing…getgrav grav
CVE-2025-66300Grav is vulnerable to Arbitrary File Readgetgrav grav
CVE-2025-66299Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMSgetgrav grav
CVE-2025-66298Grav is vulnerable to Server-Side Template Injection (SSTI) via Formsgetgrav grav
CVE-2025-66297Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injectiongetgrav grav
CVE-2025-66296Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeovergetgrav grav
CVE-2025-66295Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System…getgrav grav
CVE-2025-66294Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypassgetgrav grav
CVE-2025-64059no title heldgetgrav Grav
CVE-2024-34082Grav Arbitrary File Read to Account Takeovergetgrav grav
CVE-2024-28119Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handlergetgrav grav
CVE-2024-28118Grav vulnerable to Server Side Template Injection (SSTI)getgrav grav
CVE-2024-28117Grav vulnerable to Server Side Template Injection (SSTI)getgrav grav
CVE-2024-28116Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypassgetgrav grav
CVE-2024-27923Remote Code Execution by uploading a phar file using frontmattergetgrav grav
CVE-2024-27921Grav File Upload Path Traversal vulnerabilitygetgrav grav
CVE-2023-37897Server-side Template Injection (SSTI) in gravgetgrav grav
CVE-2023-34452Grav vulnerable to Self Cross Site Scripting in /forgot_passwordgetgrav grav
CVE-2023-34448Grav Server-side Template Injection (SSTI) via Twig Default Filtersgetgrav grav
CVE-2023-34253Grav vulnerable to Server-side Template Injection (SSTI) via Denylist Bypassgetgrav grav
CVE-2023-34252Grav Server-side Template Injection via Insufficient Validation in filterFiltergetgrav grav
CVE-2023-34251Grav Server Side Template Injection vulnerabilitygetgrav grav
CVE-2022-2073Code Injection in getgrav/gravgetgrav/grav
CVE-2022-1173stored xss in getgrav/gravgetgrav/grav
CVE-2022-0970Cross-site Scripting (XSS) - Stored in getgrav/gravgetgrav/grav
CVE-2022-0743Cross-site Scripting (XSS) - Stored in getgrav/gravgetgrav/grav
CVE-2022-0268Cross-site Scripting (XSS) - Stored in getgrav/gravgetgrav/grav
CVE-2021-47812GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)Getgrav GravCMS
CVE-2021-3924Path Traversal in getgrav/gravgetgrav/grav
CVE-2021-3920Cross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admingetgrav/grav-plugin-admin
CVE-2021-3904Cross-site Scripting (XSS) - Stored in getgrav/gravgetgrav/grav
CVE-2021-3818Reliance on Cookies without Validation and Integrity Checking in getgrav/gravgetgrav/grav
CVE-2021-3799Improper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-admingetgrav/grav-plugin-admin
CVE-2021-29440Twig allowing dangerous PHP functions by defaultgetgrav grav
CVE-2021-29439Plugins can be installed with minimal admin privilegesgetgrav grav-plugin-admin
CVE-2021-21425Unauthenticated Arbitrary YAML Write/Update leads to Code Executiongetgrav grav-plugin-admin
CVE-2020-36955Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site ScriptingGetgrav Grav CMS Admin Plugin

180 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.