Grav Data Manager 插件(getgrav/grav-plugin-datamanager)版本 1.0.1 至 1.4.4 在条目详情视图(admin/templates/partials/item.html.twig)中渲染存储的数据项时未进行转义处理,而是应用了 Twig 的 过滤器;在某些情况下,该数据会先经过 调用处理,而 PHP 的 函数在保留允许标签的同时也会保留其属性,从而可被绕过。 一名未认证的访客可以通过提交前端表单,其数据被保存至 目录,从而存储一个 HTML 载荷。当管理员后续
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| getgrav | grav-plugin-datamanager | 1.0.1 ~ 1.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100670 | 8.8 HIGH | Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass |
| CVE-2026-100671 | 8.0 HIGH | Grav before 2.0.25 Session Cookie Theft via Twig Sandbox |
| CVE-2026-100669 | 7.5 HIGH | Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass |
| CVE-2026-100672 | 7.5 HIGH | grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure |
| CVE-2026-100668 | 6.5 MEDIUM | Grav before 2.0.25 Sandbox Escape via array Filter |
| CVE-2026-100667 | 5.3 MEDIUM | grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass |
No comments yet