Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grav — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in grav, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Graviton server platform, specifically focusing on memory corruption and access control weaknesses identified through hardware abstraction layers. The collection spans advisories issued over the last five years, covering critical defects in driver interfaces and virtualization components that impact system stability and confidentiality. Readers can use this resource to track vendor-issued security notices, analyze the evolution of specific weakness classes, and review the complete vulnerability history for the Graviton product line. By examining these entries, technical teams can identify recurring patterns in firmware updates, assess potential impact on cloud workloads, and verify which patches have been applied to deployed instances. The data is organized by release version and severity rating, allowing engineers to quickly isolate relevant fixes for their infrastructure environment without needing to search multiple disparate sources. This centralized view supports proactive risk management by highlighting which specific Graviton revisions require immediate attention due to unpatched critical flaws affecting network stack integrity or privilege escalation paths within the hypervisor context.

Vendor: getgrav

CVE ID Title CVSS Severity Published
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa CWE-306 8.8 High 2026-08-14
CVE-2026-72823 Grav before 1.0.13 API-key scope cap bypass via DemoController CWE-862 5.4 Medium 2026-08-14
CVE-2026-72821 Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle CWE-79 5.4 Medium 2026-08-14
CVE-2026-72820 Grav 2.0.11 Path Traversal via Backup Profile Configuration CWE-22 4.9 Medium 2026-08-14
CVE-2026-72819 Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload CWE-94 8.8 High 2026-08-14
CVE-2026-69089 Grav CMS before 2.0.11 Path Traversal via watermark CWE-22 7.5 High 2026-08-03
CVE-2026-69088 Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint CWE-94 8.1 High 2026-08-03
CVE-2026-66400 Grav Login Plugin before 3.8.13 Insufficient Session Expiration CWE-613 4.8 Medium 2026-07-29
CVE-2026-65896 Grav API Plugin before 1.0.10 Path Traversal via move CWE-73 7.1 High 2026-07-23
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups CWE-269 8.8 High 2026-07-23
CVE-2026-65608 Grav before 2.0.9 Remote Code Execution via FlexDirectory CWE-470 8.8 High 2026-07-23
CVE-2026-65895 Grav API Plugin before 1.0.10 Broken Access Control CWE-862 8.5 High 2026-07-23
CVE-2026-65603 Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update CWE-269 8.8 High 2026-07-22
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData CWE-94 9.8 Critical 2026-07-21
CVE-2026-64628 Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers CWE-79 5.4 Medium 2026-07-21
CVE-2026-65007 Grav before 1.0.8 Missing Authorization on API Key Generation CWE-862 9.6 Critical 2026-07-21
CVE-2026-62386 Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter CWE-598 7.5 High 2026-07-17
CVE-2026-62387 Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin CWE-942 7.1 High 2026-07-17
CVE-2026-62237 Grav < 2.0.4 ReDoS via regex_replace in Sandbox CWE-1333 6.5 Medium 2026-07-17
CVE-2026-62236 grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret CWE-352 5.4 Medium 2026-07-17
CVE-2026-62234 Grav < 2.0.4 SSRF via Unrestricted cURL Protocols CWE-918 8.1 High 2026-07-17
CVE-2026-62235 Grav Flex-Objects < 1.4.3 Authorization Bypass via API CWE-862 6.3 Medium 2026-07-17
CVE-2026-62233 grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey CWE-639 8.8 High 2026-07-17
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration CWE-862 7.4 High 2026-07-17
CVE-2026-62231 Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator CWE-863 8.1 High 2026-07-17
CVE-2026-62230 Grav < 2.0.4 File Access Bypass via Case Variation CWE-178 7.5 High 2026-07-17
CVE-2026-61873 Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename CWE-73 8.1 High 2026-07-15
CVE-2026-61457 Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass CWE-434 8.8 High 2026-07-15
CVE-2026-61453 Grav before 2.0.1 XSS via Twig String Concatenation CWE-79 6.1 Medium 2026-07-15
CVE-2026-61451 Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url CWE-601 9.6 Critical 2026-07-15

All 154 known CVE vulnerabilities affecting grav with full Chinese analysis, references, and POCs where available.