Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getgrav — Vulnerabilities & Security Advisories 187

Browse all 187 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

Found 149 results / 187 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-72822 Grav before 1.0.13 Authentication Bypass via disable2fa — grav CWE-306 8.8 High 2026-08-14
CVE-2026-72823 Grav before 1.0.13 API-key scope cap bypass via DemoController — grav CWE-862 5.4 Medium 2026-08-14
CVE-2026-72821 Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle — grav CWE-79 5.4 Medium 2026-08-14
CVE-2026-72820 Grav 2.0.11 Path Traversal via Backup Profile Configuration — grav CWE-22 4.9 Medium 2026-08-14
CVE-2026-72819 Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload — grav CWE-94 8.8 High 2026-08-14
CVE-2026-69089 Grav CMS before 2.0.11 Path Traversal via watermark — grav CWE-22 7.5 High 2026-08-03
CVE-2026-69088 Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint — grav CWE-94 8.1 High 2026-08-03
CVE-2026-66400 Grav Login Plugin before 3.8.13 Insufficient Session Expiration — grav CWE-613 4.8 Medium 2026-07-29
CVE-2026-65896 Grav API Plugin before 1.0.10 Path Traversal via move — grav CWE-73 7.1 High 2026-07-23
CVE-2026-65897 Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups — grav CWE-269 8.8 High 2026-07-23
CVE-2026-65608 Grav before 2.0.9 Remote Code Execution via FlexDirectory — grav CWE-470 8.8 High 2026-07-23
CVE-2026-65895 Grav API Plugin before 1.0.10 Broken Access Control — grav CWE-862 8.5 High 2026-07-23
CVE-2026-65603 Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update — grav CWE-269 8.8 High 2026-07-22
CVE-2026-65008 Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData — grav CWE-94 9.8 Critical 2026-07-21
CVE-2026-64628 Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers — grav CWE-79 5.4 Medium 2026-07-21
CVE-2026-65007 Grav before 1.0.8 Missing Authorization on API Key Generation — grav CWE-862 9.6 Critical 2026-07-21
CVE-2026-62386 Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter — grav CWE-598 7.5 High 2026-07-17
CVE-2026-62387 Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin — grav CWE-942 7.1 High 2026-07-17
CVE-2026-62237 Grav < 2.0.4 ReDoS via regex_replace in Sandbox — grav CWE-1333 6.5 Medium 2026-07-17
CVE-2026-62236 grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret — grav CWE-352 5.4 Medium 2026-07-17
CVE-2026-62234 Grav < 2.0.4 SSRF via Unrestricted cURL Protocols — grav CWE-918 8.1 High 2026-07-17
CVE-2026-62235 Grav Flex-Objects < 1.4.3 Authorization Bypass via API — grav CWE-862 6.3 Medium 2026-07-17
CVE-2026-62233 grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey — grav CWE-639 8.8 High 2026-07-17
CVE-2026-62232 Grav < 2.0.4 2FA Bypass via Secret Regeneration — grav CWE-862 7.4 High 2026-07-17
CVE-2026-62231 Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator — grav CWE-863 8.1 High 2026-07-17
CVE-2026-62230 Grav < 2.0.4 File Access Bypass via Case Variation — grav CWE-178 7.5 High 2026-07-17
CVE-2026-61873 Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename — grav CWE-73 8.1 High 2026-07-15
CVE-2026-61457 Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass — grav CWE-434 8.8 High 2026-07-15
CVE-2026-61453 Grav before 2.0.1 XSS via Twig String Concatenation — grav CWE-79 6.1 Medium 2026-07-15
CVE-2026-61451 Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url — grav CWE-601 9.6 Critical 2026-07-15

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.