Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grav — Vulnerabilities & Security Advisories 154

All 154 CVE vulnerabilities found in grav, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the Graviton server platform, specifically focusing on memory corruption and access control weaknesses identified through hardware abstraction layers. The collection spans advisories issued over the last five years, covering critical defects in driver interfaces and virtualization components that impact system stability and confidentiality. Readers can use this resource to track vendor-issued security notices, analyze the evolution of specific weakness classes, and review the complete vulnerability history for the Graviton product line. By examining these entries, technical teams can identify recurring patterns in firmware updates, assess potential impact on cloud workloads, and verify which patches have been applied to deployed instances. The data is organized by release version and severity rating, allowing engineers to quickly isolate relevant fixes for their infrastructure environment without needing to search multiple disparate sources. This centralized view supports proactive risk management by highlighting which specific Graviton revisions require immediate attention due to unpatched critical flaws affecting network stack integrity or privilege escalation paths within the hypervisor context.

Vendor: getgrav

CVE ID Title CVSS Severity Published
CVE-2026-61452 Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens CWE-613 5.3 Medium 2026-07-15
CVE-2026-61449 Grav before 2.0.2 Decompression Bomb via Forged ZIP Size CWE-409 6.5 Medium 2026-07-15
CVE-2026-58655 Grav Flex Objects - Server-Side Template Injection via Dynamic Titles CWE-94 8.8 High 2026-07-15
CVE-2026-61454 Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ CWE-200 5.3 Medium 2026-07-11
CVE-2026-59193 Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip() CWE-409 - - 2026-07-10
CVE-2026-59190 Grav Admin Plugin — IDOR Privilege Escalation via saveUser() CWE-639 - - 2026-07-10
CVE-2026-58493 grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction CWE-74 - - 2026-07-10
CVE-2026-58492 grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation CWE-89 - - 2026-07-10
CVE-2026-55890 Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() CWE-79 4.8 Medium 2026-07-10
CVE-2026-55885 Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets CWE-312 6.8 Medium 2026-07-10
CVE-2026-53653 Grav: Unauthenticated denial of service via unbounded image derivative dimensions CWE-770 - - 2026-07-10
CVE-2026-61456 Grav before 1.0.3 Stored XSS via SVG Upload API CWE-79 4.6 Medium 2026-07-10
CVE-2026-61455 Grav before 2.0.1 Decompression Bomb via ZipArchiver CWE-409 6.5 Medium 2026-07-10
CVE-2026-61450 Grav before 2.0.2 Config Exfiltration via offsetGet Filter CWE-94 6.5 Medium 2026-07-10
CVE-2026-58657 Grav - Stored CSS Injection via Markdown Image resize() Action CWE-79 4.8 Medium 2026-07-08
CVE-2026-58656 Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter CWE-598 7.5 High 2026-07-08
CVE-2026-58654 Grav - Arbitrary File Upload via Avatar Endpoint CWE-434 4.3 Medium 2026-07-08
CVE-2026-56700 Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection CWE-78 9.8 Critical 2026-06-30
CVE-2020-37256 Grav - Cross-Site Scripting in Admin Plugin Page Editor CWE-79 5.4 Medium 2026-06-25
CVE-2026-56701 Grav - XML External Entity Injection via SVG Upload CWE-611 6.5 Medium 2026-06-23
CVE-2026-42844 Grav: Low-privileged API users can create super-admin accounts via blueprint-upload CWE-434 - - 2026-05-12
CVE-2026-44738 Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray() CWE-200 7.7 High 2026-05-11
CVE-2026-42842 grav-plugin-form: XSS via Taxonomy Field Values in Admin Panel CWE-79 5.4 Medium 2026-05-11
CVE-2026-42613 Grav: Privilege Escalation via Missing Server-Side Validation of groups/access CWE-20 9.4 Critical 2026-05-11
CVE-2026-42612 Grav: Publisher-Level Stored XSS via Unquoted Event Attributes CWE-79 8.5 High 2026-05-11
CVE-2026-42611 Grav: Stored XSS via Tag Injection CWE-79 8.9 High 2026-05-11
CVE-2026-42610 Grav: Sensitive Information Disclosure via Accounts Service Bypass CWE-863 6.5 Medium 2026-05-11
CVE-2026-42609 Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic CWE-269 8.1 High 2026-05-11
CVE-2026-42608 Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component. CWE-22 - - 2026-05-11
CVE-2026-42607 Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature CWE-94 9.1 Critical 2026-05-11

All 154 known CVE vulnerabilities affecting grav with full Chinese analysis, references, and POCs where available.