Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getgrav — Vulnerabilities & Security Advisories 187

Browse all 187 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

CVE ID Title CVSS Severity Published
CVE-2026-75832 Grav API Plugin before 1.0.14 Authorization Bypass — grav CWE-862 4.3 Medium 2026-08-18
CVE-2026-75833 Grav API Plugin Open Redirect via Backslash Bypass — grav CWE-601 4.2 Medium 2026-08-18
CVE-2026-75831 Grav before 2.0.15 Stored XSS via audio/video source URL — grav CWE-79 7.6 High 2026-08-18
CVE-2026-75829 grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint — grav CWE-1336 8.1 High 2026-08-18
CVE-2026-75830 grav-plugin-api before 1.0.15 Path Traversal via batchCopy — grav CWE-73 7.1 High 2026-08-18
CVE-2026-75828 Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass — grav CWE-79 8.7 High 2026-08-18
CVE-2026-75827 Grav before 2.0.15 Arbitrary File Write via error_log — grav CWE-94 8.8 High 2026-08-18
CVE-2026-75107 Grav Form Plugin before 9.1.19 Stored XSS via Field Properties — grav CWE-79 5.4 Medium 2026-08-18
CVE-2026-74908 Grav plugin-api before 1.0.15 Script Injection via SVG — grav CWE-79 4.6 Medium 2026-08-18
CVE-2026-74907 Grav before 2.0.15 Path Traversal via plugin-asset-map.php — grav CWE-22 5.9 Medium 2026-08-18
CVE-2026-72833 Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys — grav-plugin-api CWE-269 8.8 High 2026-08-14
CVE-2026-72831 Grav through 2.0.11 Authentication Bypass via Flex Objects — grav CWE-863 8.8 High 2026-08-14
CVE-2026-72832 Grav before 2.0.12 Stored XSS via quoted-attribute bypass — grav CWE-79 5.4 Medium 2026-08-14
CVE-2026-72830 Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass — grav CWE-269 8.8 High 2026-08-14
CVE-2026-72829 Grav before 1.0.13 API Key Scope Bypass via UsersController — grav CWE-269 8.8 High 2026-08-14
CVE-2026-72828 Grav before 1.0.13 API Key Scope Bypass via InvitationsController — grav CWE-269 7.2 High 2026-08-14
CVE-2026-72827 Grav CMS before 2.0.13 Remote Code Execution via Twig — grav CWE-1336 8.8 High 2026-08-14
CVE-2026-72825 Grav before 1.0.13 API-key scope cap bypass via ReportsController — grav CWE-862 7.6 High 2026-08-14
CVE-2026-72826 Grav before 1.0.13 Scope Bypass via createApiKey — grav CWE-266 8.8 High 2026-08-14
CVE-2026-72824 Grav before 1.0.13 API Key Scope Bypass via PagesController — grav CWE-862 8.8 High 2026-08-14
CVE-2026-72823 Grav before 1.0.13 API-key scope cap bypass via DemoController — grav CWE-862 5.4 Medium 2026-08-14
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa — grav CWE-306 8.8 High 2026-08-14
CVE-2026-72821 Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle — grav CWE-79 5.4 Medium 2026-08-14
CVE-2026-72819 Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload — grav CWE-94 8.8 High 2026-08-14
CVE-2026-72820 Grav 2.0.11 Path Traversal via Backup Profile Configuration — grav CWE-22 4.9 Medium 2026-08-14
CVE-2026-69089 Grav CMS before 2.0.11 Path Traversal via watermark — grav CWE-22 7.5 High 2026-08-03
CVE-2026-69088 Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint — grav CWE-94 8.1 High 2026-08-03
CVE-2026-69087 Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig — grav-plugin-form CWE-601 6.5 Medium 2026-08-03
CVE-2026-66400 Grav Login Plugin before 3.8.13 Insufficient Session Expiration — grav CWE-613 4.8 Medium 2026-07-29
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups — grav CWE-269 8.8 High 2026-07-23

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.