Grav
This hub aggregates every CVE we track for Grav, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
157
CVEs tracked
15
Critical
73
High
0
In CISA KEV
Severity distribution
HIGH73MEDIUM68CRITICAL15LOW1
Monthly trend
0
0
0
1
0
0
0
0
0
2
1
0
0
1
22
1
0
1
0
11
3
36
50
4
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Grav.
- CVE-2026-85604Grav before 2.0.18 Remote Code Execution via sort filter8.8
- CVE-2026-85603Grav Admin Plugin Path Traversal via Save As Language Code6.5
- CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.js5.4
- CVE-2026-85598Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages6.4
- CVE-2026-80204Grav before 1.0.18 Authentication Bypass via Scoped API Key5.4
- CVE-2026-80203Grav before 1.0.18 Authentication Bypass via Scoped API Key9.8
- CVE-2026-76846Grav before 2.0.16 Information Disclosure via Twig Sandbox7.5
- CVE-2026-76839Grav before 2.0.16 Information Disclosure via offsetGet6.5
- CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twig8.8
- CVE-2026-72702Grav CMS before 2.0.16 Origin Validation Bypass via Referer5.4
- CVE-2026-72701Grav CMS before 2.0.16 Timing Attack via verifyNonce3.7
- CVE-2026-72700Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison7.5
- CVE-2026-72698Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass6.5
- CVE-2026-72697Grav CMS before 2.0.16 Path Traversal via media_directory6.5
- CVE-2026-72696Grav CMS before 2.0.16 Symlink Following via createLockFile8.4
Product normalization is registry-driven with AI assist and human review. How it works