Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getgrav — Vulnerabilities & Security Advisories 187

Browse all 187 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

Found 149 results / 187 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-100670 Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass — grav CWE-639 8.8 High 2026-09-26
CVE-2026-100671 Grav before 2.0.25 Session Cookie Theft via Twig Sandbox — grav CWE-200 8.0 High 2026-09-26
CVE-2026-100669 Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass — grav CWE-178 7.5 High 2026-09-26
CVE-2026-100668 Grav before 2.0.25 Sandbox Escape via array Filter — grav CWE-200 6.5 Medium 2026-09-26
CVE-2026-100667 grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass — grav CWE-304 5.3 Medium 2026-09-26
CVE-2026-92917 Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r — grav CWE-200 7.5 High 2026-09-17
CVE-2026-92916 Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork — grav CWE-200 7.5 High 2026-09-17
CVE-2025-64059 Grav 跨站脚本漏洞 — Grav CWE-79 1.8 Low 2026-09-13
CVE-2026-86197 Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox — grav CWE-79 5.1 Medium 2026-09-05
CVE-2026-85604 Grav before 2.0.18 Remote Code Execution via sort filter — grav CWE-94 8.8 High 2026-09-04
CVE-2026-85603 Grav Admin Plugin Path Traversal via Save As Language Code — grav CWE-73 6.5 Medium 2026-09-04
CVE-2026-85601 Grav Admin before 2.0.20 Cross-Site Scripting via marked.js — grav CWE-79 5.4 Medium 2026-09-04
CVE-2026-85598 Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages — grav CWE-79 6.4 Medium 2026-09-04
CVE-2026-80204 Grav before 1.0.18 Authentication Bypass via Scoped API Key — grav CWE-863 5.4 Medium 2026-08-26
CVE-2026-80203 Grav before 1.0.18 Authentication Bypass via Scoped API Key — grav CWE-863 9.8 Critical 2026-08-26
CVE-2026-76846 Grav before 2.0.16 Information Disclosure via Twig Sandbox — grav CWE-522 7.5 High 2026-08-25
CVE-2026-76839 Grav before 2.0.16 Information Disclosure via offsetGet — grav CWE-522 6.5 Medium 2026-08-25
CVE-2026-75574 Grav before 4.2.2 Remote Code Execution via Email Twig — grav CWE-1336 8.8 High 2026-08-25
CVE-2026-72702 Grav CMS before 2.0.16 Origin Validation Bypass via Referer — grav CWE-346 5.4 Medium 2026-08-25
CVE-2026-72701 Grav CMS before 2.0.16 Timing Attack via verifyNonce — grav CWE-208 3.7 Low 2026-08-25
CVE-2026-72700 Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison — grav CWE-208 7.5 High 2026-08-25
CVE-2026-72698 Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass — grav CWE-200 6.5 Medium 2026-08-25
CVE-2026-72697 Grav CMS before 2.0.16 Path Traversal via media_directory — grav CWE-22 6.5 Medium 2026-08-25
CVE-2026-72696 Grav CMS before 2.0.16 Symlink Following via createLockFile — grav CWE-59 8.4 High 2026-08-25
CVE-2026-72695 Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile — grav CWE-22 8.1 High 2026-08-25
CVE-2026-56710 Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock — grav CWE-863 9.8 Critical 2026-08-25
CVE-2026-56709 Grav before 3.9.2 Host Header Injection via sendInvitationEmail — grav CWE-350 7.5 High 2026-08-25
CVE-2026-56708 Grav API Plugin before 1.0.16 SSRF via DNS Rebinding — grav CWE-367 5.3 Medium 2026-08-25
CVE-2026-56707 Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode — grav CWE-862 7.7 High 2026-08-25
CVE-2026-64850 Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() — grav CWE-94 8.7 High 2026-08-19

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.