Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

getgrav — Vulnerabilities & Security Advisories 117

Browse all 117 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

CVE IDTitleCVSSSeverityPublished
CVE-2026-72833 Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys — gravCWE-269 8.8 High2026-08-14
CVE-2026-72831 Grav through 2.0.11 Authentication Bypass via Flex Objects — gravCWE-863 8.8 High2026-08-14
CVE-2026-72832 Grav before 2.0.12 Stored XSS via quoted-attribute bypass — gravCWE-79 5.4 Medium2026-08-14
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass — gravCWE-269 9.8 Critical2026-08-14
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController — gravCWE-269 9.8 Critical2026-08-14
CVE-2026-72828 Grav before 1.0.13 API Key Scope Bypass via InvitationsController — gravCWE-269 7.2 High2026-08-14
CVE-2026-72827 Grav CMS before 2.0.13 Remote Code Execution via Twig — gravCWE-1336 8.8 High2026-08-14
CVE-2026-72825 Grav before 1.0.13 API-key scope cap bypass via ReportsController — gravCWE-862 7.6 High2026-08-14
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey — gravCWE-266 9.8 Critical2026-08-14
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController — gravCWE-862 9.8 Critical2026-08-14
CVE-2026-72823 Grav before 1.0.13 API-key scope cap bypass via DemoController — gravCWE-862 5.4 Medium2026-08-14
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa — gravCWE-306 9.8 Critical2026-08-14
CVE-2026-72821 Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle — gravCWE-79 5.4 Medium2026-08-14
CVE-2026-72819 Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload — gravCWE-94 8.8 High2026-08-14
CVE-2026-72820 Grav 2.0.11 Path Traversal via Backup Profile Configuration — gravCWE-22 4.9 Medium2026-08-14
CVE-2026-69089 Grav CMS before 2.0.11 Path Traversal via watermark — gravCWE-22 7.5 High2026-08-03
CVE-2026-69088 Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint — gravCWE-94 8.1 High2026-08-03
CVE-2026-69087 Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig — grav-plugin-formCWE-601 6.5 Medium2026-08-03
CVE-2026-66400 Grav Login Plugin before 3.8.13 Insufficient Session Expiration — gravCWE-613 4.8 Medium2026-07-29
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups — gravCWE-269 8.8 High2026-07-23
CVE-2026-65896 Grav API Plugin before 1.0.10 Path Traversal via move — gravCWE-73 7.1 High2026-07-23
CVE-2026-65895 Grav API Plugin before 1.0.10 Broken Access Control — gravCWE-862 8.5 High2026-07-23
CVE-2026-65608 Grav before 2.0.9 Remote Code Execution via FlexDirectory — gravCWE-470 8.8 High2026-07-23
CVE-2026-65603 Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update — gravCWE-269 8.8 High2026-07-22
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData — gravCWE-94 9.8 Critical2026-07-21
CVE-2026-65007 Grav before 1.0.8 Missing Authorization on API Key Generation — gravCWE-862 9.6 Critical2026-07-21
CVE-2026-64628 Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers — gravCWE-79 5.4 Medium2026-07-21
CVE-2026-62386 Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter — gravCWE-598 7.5 High2026-07-17
CVE-2026-62387 Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin — gravCWE-942 7.1 High2026-07-17
CVE-2026-62237 Grav < 2.0.4 ReDoS via regex_replace in Sandbox — gravCWE-1333 6.5 Medium2026-07-17

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.