Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

getgrav — Vulnerabilities & Security Advisories 148

Browse all 148 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

CVE ID Title CVSS Severity Published
CVE-2026-64852 Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account — grav-plugin-api CWE-862 8.7 High 2026-08-19
CVE-2026-64850 Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() — grav CWE-94 8.7 High 2026-08-19
CVE-2026-64851 Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers — grav-plugin-shortcode-core CWE-79 8.5 High 2026-08-19
CVE-2026-63408 Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter — grav-plugin-api CWE-598 7.5 High 2026-08-19
CVE-2026-63407 Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses — grav-plugin-api CWE-942 8.2 High 2026-08-19
CVE-2026-62671 CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret) — grav-plugin-login CWE-352 5.4 Medium 2026-08-19
CVE-2026-62673 Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems — grav CWE-178 8.2 High 2026-08-19
CVE-2026-62672 Grav: Authenticated ReDoS via regex_replace in Twig Sandbox — grav CWE-1333 6.0 Medium 2026-08-19
CVE-2026-62667 Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL — grav-plugin-api CWE-862 8.1 High 2026-08-19
CVE-2026-62669 Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge — grav CWE-287 7.4 High 2026-08-19
CVE-2026-62666 Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super — grav-plugin-api CWE-639 8.8 High 2026-08-19
CVE-2026-62668 Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols — grav CWE-918 9.4 Critical 2026-08-19
CVE-2026-62670 Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny) — grav-plugin-flex-objects CWE-862 6.3 Medium 2026-08-19
CVE-2026-61842 Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) — grav CWE-200 6.5 Medium 2026-08-19
CVE-2026-61690 Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits — grav CWE-409 6.5 Medium 2026-08-19
CVE-2026-61607 Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer — grav-plugin-api CWE-79 4.6 Medium 2026-08-19
CVE-2026-53654 Grav: Unauthenticated open redirect via login twofa_cancel _redirect — grav CWE-601 5.3 Medium 2026-08-19
CVE-2026-75837 Grav before 2.0.14 Privilege Escalation via Group Access Field — grav CWE-269 9.1 Critical 2026-08-18
CVE-2026-75836 Grav API Plugin before 1.0.14 Missing Authorization — grav CWE-862 8.8 High 2026-08-18
CVE-2026-75835 Grav API Plugin before 1.0.14 Missing Authorization — grav CWE-862 4.3 Medium 2026-08-18
CVE-2026-75834 Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte — grav CWE-79 5.4 Medium 2026-08-18
CVE-2026-75833 Grav API Plugin Open Redirect via Backslash Bypass — grav CWE-601 4.2 Medium 2026-08-18
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass — grav CWE-862 4.3 Medium 2026-08-18
CVE-2026-75831 Grav before 2.0.15 Stored XSS via audio/video source URL — grav CWE-79 7.6 High 2026-08-18
CVE-2026-75829 grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint — grav CWE-1336 8.1 High 2026-08-18
CVE-2026-75830 grav-plugin-api before 1.0.15 Path Traversal via batchCopy — grav CWE-73 7.1 High 2026-08-18
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass — grav CWE-79 8.7 High 2026-08-18
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log — grav CWE-94 8.8 High 2026-08-18
CVE-2026-75107 Grav Form Plugin before 9.1.19 Stored XSS via Field Properties — grav CWE-79 5.4 Medium 2026-08-18
CVE-2026-74908 Grav plugin-api before 1.0.15 Script Injection via SVG — grav CWE-79 4.6 Medium 2026-08-18

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.