All 3 CVE vulnerabilities found in grav-plugin-admin, with AI-generated Chinese analysis, references, and POCs.
Vendor: getgrav
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44737 | grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][title] CWE-79 | - | - | 2026-05-11 |
| CVE-2021-29439 | Plugins can be installed with minimal admin privileges CWE-863 | 7.2 | High | 2021-04-13 |
| CVE-2021-21425 | Unauthenticated Arbitrary YAML Write/Update leads to Code Execution CWE-284 | 9.3 | Critical | 2021-04-07 |
All 3 known CVE vulnerabilities affecting grav-plugin-admin with full Chinese analysis, references, and POCs where available.