Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grav — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in grav, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Graviton server platform, specifically focusing on memory corruption and access control weaknesses identified through hardware abstraction layers. The collection spans advisories issued over the last five years, covering critical defects in driver interfaces and virtualization components that impact system stability and confidentiality. Readers can use this resource to track vendor-issued security notices, analyze the evolution of specific weakness classes, and review the complete vulnerability history for the Graviton product line. By examining these entries, technical teams can identify recurring patterns in firmware updates, assess potential impact on cloud workloads, and verify which patches have been applied to deployed instances. The data is organized by release version and severity rating, allowing engineers to quickly isolate relevant fixes for their infrastructure environment without needing to search multiple disparate sources. This centralized view supports proactive risk management by highlighting which specific Graviton revisions require immediate attention due to unpatched critical flaws affecting network stack integrity or privilege escalation paths within the hypervisor context.

Vendor: getgrav

CVE ID Title CVSS Severity Published
CVE-2026-100670 Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass CWE-639 8.8 High 2026-09-26
CVE-2026-100671 Grav before 2.0.25 Session Cookie Theft via Twig Sandbox CWE-200 8.0 High 2026-09-26
CVE-2026-100669 Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass CWE-178 7.5 High 2026-09-26
CVE-2026-100668 Grav before 2.0.25 Sandbox Escape via array Filter CWE-200 6.5 Medium 2026-09-26
CVE-2026-100667 grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass CWE-304 5.3 Medium 2026-09-26
CVE-2026-92917 Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r CWE-200 7.5 High 2026-09-17
CVE-2026-92916 Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork CWE-200 7.5 High 2026-09-17
CVE-2025-64059 Grav 跨站脚本漏洞 CWE-79 1.8 Low 2026-09-13
CVE-2026-86197 Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox CWE-79 5.1 Medium 2026-09-05
CVE-2026-85604 Grav before 2.0.18 Remote Code Execution via sort filter CWE-94 8.8 High 2026-09-04
CVE-2026-85603 Grav Admin Plugin Path Traversal via Save As Language Code CWE-73 6.5 Medium 2026-09-04
CVE-2026-85601 Grav Admin before 2.0.20 Cross-Site Scripting via marked.js CWE-79 5.4 Medium 2026-09-04
CVE-2026-85598 Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages CWE-79 6.4 Medium 2026-09-04
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key CWE-863 5.4 Medium 2026-08-26
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key CWE-863 9.8 Critical 2026-08-26
CVE-2026-76846 Grav before 2.0.16 Information Disclosure via Twig Sandbox CWE-522 7.5 High 2026-08-25
CVE-2026-76839 Grav before 2.0.16 Information Disclosure via offsetGet CWE-522 6.5 Medium 2026-08-25
CVE-2026-75574 Grav before 4.2.2 Remote Code Execution via Email Twig CWE-1336 8.8 High 2026-08-25
CVE-2026-72702 Grav CMS before 2.0.16 Origin Validation Bypass via Referer CWE-346 5.4 Medium 2026-08-25
CVE-2026-72701 Grav CMS before 2.0.16 Timing Attack via verifyNonce CWE-208 3.7 Low 2026-08-25
CVE-2026-72700 Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison CWE-208 7.5 High 2026-08-25
CVE-2026-72698 Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass CWE-200 6.5 Medium 2026-08-25
CVE-2026-72697 Grav CMS before 2.0.16 Path Traversal via media_directory CWE-22 6.5 Medium 2026-08-25
CVE-2026-72696 Grav CMS before 2.0.16 Symlink Following via createLockFile CWE-59 8.4 High 2026-08-25
CVE-2026-72695 Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile CWE-22 8.1 High 2026-08-25
CVE-2026-56710 Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock CWE-863 9.8 Critical 2026-08-25
CVE-2026-56709 Grav before 3.9.2 Host Header Injection via sendInvitationEmail CWE-350 7.5 High 2026-08-25
CVE-2026-56708 Grav API Plugin before 1.0.16 SSRF via DNS Rebinding CWE-367 5.3 Medium 2026-08-25
CVE-2026-56707 Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode CWE-862 7.7 High 2026-08-25
CVE-2026-64850 Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() CWE-94 8.7 High 2026-08-19

All 154 known CVE vulnerabilities affecting grav with full Chinese analysis, references, and POCs where available.