Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100673— Grav Data Manager before 1.4.5 Stored XSS via item-detail view

Quick assessment

Affected
getgrav grav-plugin-datamanager
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Grav Data Manager 插件(getgrav/grav-plugin-datamanager)版本 1.0.1 至 1.4.4 在条目详情视图(admin/templates/partials/item.html.twig)中渲染存储的数据项时未进行转义处理,而是应用了 Twig 的 过滤器;在某些情况下,该数据会先经过 调用处理,而 PHP 的 函数在保留允许标签的同时也会保留其属性,从而可被绕过。 一名未认证的访客可以通过提交前端表单,其数据被保存至 目录,从而存储一个 HTML 载荷。当管理员后续

CVSS 8.2 · High EPSS 0.29% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100673

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Grav Data Manager before 1.4.5 Stored XSS via item-detail view
Source: CVE Program / CVE List V5
Vulnerability Description
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
getgrav grav-plugin-datamanager 1.0.1 ~ 1.4.5 -

II. Public POCs for CVE-2026-100673

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100673

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100673 (2)

Same Patch Batch · getgrav · 2026-09-26 · 7 CVEs total

CVE-2026-100670 8.8 HIGH Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass
CVE-2026-100671 8.0 HIGH Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
CVE-2026-100669 7.5 HIGH Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass
CVE-2026-100672 7.5 HIGH grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure
CVE-2026-100668 6.5 MEDIUM Grav before 2.0.25 Sandbox Escape via array Filter
CVE-2026-100667 5.3 MEDIUM grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-100673

No comments yet


Leave a comment