Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

getgrav — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

CVE IDTitleCVSSSeverityPublished
CVE-2026-62387 Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin — gravCWE-942 7.1 High2026-07-17
CVE-2026-62386 Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter — gravCWE-598 7.5 High2026-07-17
CVE-2026-62237 Grav < 2.0.4 ReDoS via regex_replace in Sandbox — gravCWE-1333 6.5 Medium2026-07-17
CVE-2026-62236 grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret — gravCWE-352 5.4 Medium2026-07-17
CVE-2026-62235 Grav Flex-Objects < 1.4.3 Authorization Bypass via API — gravCWE-862 6.3 Medium2026-07-17
CVE-2026-62234 Grav < 2.0.4 SSRF via Unrestricted cURL Protocols — gravCWE-918 8.1 High2026-07-17
CVE-2026-62233 grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey — gravCWE-639 8.8 High2026-07-17
CVE-2026-62231 Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator — gravCWE-863 8.1 High2026-07-17
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration — gravCWE-862 7.4 High2026-07-17
CVE-2026-62230 Grav < 2.0.4 File Access Bypass via Case Variation — gravCWE-178 7.5 High2026-07-17
CVE-2026-61873 Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename — gravCWE-73 8.1 High2026-07-15
CVE-2026-61457 Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass — gravCWE-434 8.8 High2026-07-15
CVE-2026-61453 Grav before 2.0.1 XSS via Twig String Concatenation — gravCWE-79 6.1 Medium2026-07-15
CVE-2026-61451 Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url — gravCWE-601 9.6 Critical2026-07-15
CVE-2026-61452 Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens — gravCWE-613 5.3 Medium2026-07-15
CVE-2026-61449 Grav before 2.0.2 Decompression Bomb via Forged ZIP Size — gravCWE-409 6.5 Medium2026-07-15
CVE-2026-58655 Grav Flex Objects - Server-Side Template Injection via Dynamic Titles — gravCWE-94 8.8 High2026-07-15
CVE-2026-61454 Grav before 2.0.4 Information Disclosure via __GRAV_CONFIG__ — gravCWE-200 5.3 Medium2026-07-11
CVE-2026-59193 Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip() — gravCWE-409--2026-07-10
CVE-2026-59190 Grav Admin Plugin — IDOR Privilege Escalation via saveUser() — gravCWE-639--2026-07-10
CVE-2026-58493 grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction — gravCWE-74--2026-07-10
CVE-2026-58492 grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation — gravCWE-89--2026-07-10
CVE-2026-55890 Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — gravCWE-79 4.8 Medium2026-07-10
CVE-2026-55885 Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets — gravCWE-312 6.8 Medium2026-07-10
CVE-2026-53653 Grav: Unauthenticated denial of service via unbounded image derivative dimensions — gravCWE-770--2026-07-10
CVE-2026-61456 Grav before 1.0.3 Stored XSS via SVG Upload API — gravCWE-79 4.6 Medium2026-07-10
CVE-2026-61455 Grav before 2.0.1 Decompression Bomb via ZipArchiver — gravCWE-409 6.5 Medium2026-07-10
CVE-2026-61450 Grav before 2.0.2 Config Exfiltration via offsetGet Filter — gravCWE-94 6.5 Medium2026-07-10
CVE-2026-58656 Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter — gravCWE-598 7.5 High2026-07-08
CVE-2026-42844 Grav: Low-privileged API users can create super-admin accounts via blueprint-upload — gravCWE-434--2026-05-12

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.