Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getgrav — Vulnerabilities & Security Advisories 187

Browse all 187 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

CVE ID Title CVSS Severity Published
CVE-2026-100673 Grav Data Manager before 1.4.5 Stored XSS via item-detail view — grav-plugin-datamanager CWE-79 8.2 High 2026-09-26
CVE-2026-100672 grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure — grav-plugin-comments CWE-306 7.5 High 2026-09-26
CVE-2026-100670 Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass — grav CWE-639 8.8 High 2026-09-26
CVE-2026-100671 Grav before 2.0.25 Session Cookie Theft via Twig Sandbox — grav CWE-200 8.0 High 2026-09-26
CVE-2026-100669 Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass — grav CWE-178 7.5 High 2026-09-26
CVE-2026-100668 Grav before 2.0.25 Sandbox Escape via array Filter — grav CWE-200 6.5 Medium 2026-09-26
CVE-2026-100667 grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass — grav CWE-304 5.3 Medium 2026-09-26
CVE-2026-92917 Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r — grav CWE-200 7.5 High 2026-09-17
CVE-2026-92916 Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork — grav CWE-200 7.5 High 2026-09-17
CVE-2025-64059 Grav 跨站脚本漏洞 — Grav CWE-79 1.8 Low 2026-09-13
CVE-2026-86197 Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox — grav CWE-79 5.1 Medium 2026-09-05
CVE-2026-86195 grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag — grav-plugin-api CWE-269 8.7 High 2026-09-05
CVE-2026-86196 Grav API Plugin before 1.0.20 Authentication Bypass via Host Header — grav-plugin-api CWE-290 8.7 High 2026-09-05
CVE-2026-86194 Grav Form Plugin before 9.1.22 Cross-Page Form Execution — grav-plugin-form CWE-862 6.9 Medium 2026-09-05
CVE-2026-86193 Grav API Plugin Authentication Bypass via Group-Inherited Super — grav-plugin-api CWE-863 8.7 High 2026-09-05
CVE-2026-85604 Grav before 2.0.18 Remote Code Execution via sort filter — grav CWE-94 8.8 High 2026-09-04
CVE-2026-85603 Grav Admin Plugin Path Traversal via Save As Language Code — grav CWE-73 6.5 Medium 2026-09-04
CVE-2026-85602 Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass — grav-plugin-form CWE-807 5.3 Medium 2026-09-04
CVE-2026-85601 Grav Admin before 2.0.20 Cross-Site Scripting via marked.js — grav CWE-79 5.4 Medium 2026-09-04
CVE-2026-85600 Grav Admin before 2.0.21 Stored XSS via username — grav-plugin-admin2 CWE-79 5.4 Medium 2026-09-04
CVE-2026-85599 Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters — grav-plugin-shortcode-core CWE-79 7.2 High 2026-09-04
CVE-2026-85598 Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages — grav CWE-79 6.4 Medium 2026-09-04
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key — grav CWE-863 5.4 Medium 2026-08-26
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key — grav CWE-863 9.8 Critical 2026-08-26
CVE-2026-76846 Grav before 2.0.16 Information Disclosure via Twig Sandbox — grav CWE-522 7.5 High 2026-08-25
CVE-2026-76839 Grav before 2.0.16 Information Disclosure via offsetGet — grav CWE-522 6.5 Medium 2026-08-25
CVE-2026-75574 Grav before 4.2.2 Remote Code Execution via Email Twig — grav CWE-1336 8.8 High 2026-08-25
CVE-2026-72702 Grav CMS before 2.0.16 Origin Validation Bypass via Referer — grav CWE-346 5.4 Medium 2026-08-25
CVE-2026-72701 Grav CMS before 2.0.16 Timing Attack via verifyNonce — grav CWE-208 3.7 Low 2026-08-25
CVE-2026-72700 Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison — grav CWE-208 7.5 High 2026-08-25

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.