Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grav — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in grav, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Graviton server platform, specifically focusing on memory corruption and access control weaknesses identified through hardware abstraction layers. The collection spans advisories issued over the last five years, covering critical defects in driver interfaces and virtualization components that impact system stability and confidentiality. Readers can use this resource to track vendor-issued security notices, analyze the evolution of specific weakness classes, and review the complete vulnerability history for the Graviton product line. By examining these entries, technical teams can identify recurring patterns in firmware updates, assess potential impact on cloud workloads, and verify which patches have been applied to deployed instances. The data is organized by release version and severity rating, allowing engineers to quickly isolate relevant fixes for their infrastructure environment without needing to search multiple disparate sources. This centralized view supports proactive risk management by highlighting which specific Graviton revisions require immediate attention due to unpatched critical flaws affecting network stack integrity or privilege escalation paths within the hypervisor context.

Vendor: getgrav

CVE ID Title CVSS Severity Published
CVE-2026-62673 Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems CWE-178 8.2 High 2026-08-19
CVE-2026-62672 Grav: Authenticated ReDoS via regex_replace in Twig Sandbox CWE-1333 6.0 Medium 2026-08-19
CVE-2026-62669 Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge CWE-287 7.4 High 2026-08-19
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols CWE-918 9.4 Critical 2026-08-19
CVE-2026-61842 Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) CWE-200 6.5 Medium 2026-08-19
CVE-2026-61690 Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits CWE-409 6.5 Medium 2026-08-19
CVE-2026-53654 Grav: Unauthenticated open redirect via login twofa_cancel _redirect CWE-601 5.3 Medium 2026-08-19
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field CWE-269 9.1 Critical 2026-08-18
CVE-2026-75836 Grav API Plugin before 1.0.14 Missing Authorization CWE-862 8.8 High 2026-08-18
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization CWE-862 4.3 Medium 2026-08-18
CVE-2026-75834 Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte CWE-79 5.4 Medium 2026-08-18
CVE-2026-75833 Grav API Plugin Open Redirect via Backslash Bypass CWE-601 4.2 Medium 2026-08-18
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass CWE-862 4.3 Medium 2026-08-18
CVE-2026-75831 Grav before 2.0.15 Stored XSS via audio/video source URL CWE-79 7.6 High 2026-08-18
CVE-2026-75830 grav-plugin-api before 1.0.15 Path Traversal via batchCopy CWE-73 7.1 High 2026-08-18
CVE-2026-75829 grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint CWE-1336 8.1 High 2026-08-18
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass CWE-79 8.7 High 2026-08-18
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log CWE-94 8.8 High 2026-08-18
CVE-2026-75107 Grav Form Plugin before 9.1.19 Stored XSS via Field Properties CWE-79 5.4 Medium 2026-08-18
CVE-2026-74908 Grav plugin-api before 1.0.15 Script Injection via SVG CWE-79 4.6 Medium 2026-08-18
CVE-2026-74907 Grav before 2.0.15 Path Traversal via plugin-asset-map.php CWE-22 5.9 Medium 2026-08-18
CVE-2026-72831 Grav through 2.0.11 Authentication Bypass via Flex Objects CWE-863 8.8 High 2026-08-14
CVE-2026-72832 Grav before 2.0.12 Stored XSS via quoted-attribute bypass CWE-79 5.4 Medium 2026-08-14
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass CWE-269 8.8 High 2026-08-14
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController CWE-269 8.8 High 2026-08-14
CVE-2026-72828 Grav before 1.0.13 API Key Scope Bypass via InvitationsController CWE-269 7.2 High 2026-08-14
CVE-2026-72827 Grav CMS before 2.0.13 Remote Code Execution via Twig CWE-1336 8.8 High 2026-08-14
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey CWE-266 8.8 High 2026-08-14
CVE-2026-72825 Grav before 1.0.13 API-key scope cap bypass via ReportsController CWE-862 7.6 High 2026-08-14
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController CWE-862 8.8 High 2026-08-14

All 154 known CVE vulnerabilities affecting grav with full Chinese analysis, references, and POCs where available.