getgrav
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting getgrav.
- CVE-2026-85604Grav before 2.0.18 Remote Code Execution via sort filter8.8
- CVE-2026-85603Grav Admin Plugin Path Traversal via Save As Language Code6.5
- CVE-2026-85602Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass5.3
- CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.js5.4
- CVE-2026-85599Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters7.2
- CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via username5.4
- CVE-2026-85598Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages6.4
- CVE-2026-80204Grav before 1.0.18 Authentication Bypass via Scoped API Key5.4
- CVE-2026-80203Grav before 1.0.18 Authentication Bypass via Scoped API Key9.8
- CVE-2026-76846Grav before 2.0.16 Information Disclosure via Twig Sandbox7.5
- CVE-2026-76839Grav before 2.0.16 Information Disclosure via offsetGet6.5
- CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twig8.8
- CVE-2026-72702Grav CMS before 2.0.16 Origin Validation Bypass via Referer5.4
- CVE-2026-72701Grav CMS before 2.0.16 Timing Attack via verifyNonce3.7
- CVE-2026-72700Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison7.5