Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

getgrav — Vulnerabilities & Security Advisories 187

Browse all 187 CVE security advisories affecting getgrav. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GetGrav is a flat-file CMS designed for developers seeking a modern, flexible alternative to database-driven platforms. Its architecture eliminates traditional SQL dependencies, relying instead on YAML configuration and Markdown content. However, this design has historically exposed the platform to significant security risks, resulting in forty-seven recorded CVEs. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation flaws, often stemming from inadequate input validation or insecure file handling mechanisms. Notable incidents have highlighted weaknesses in plugin ecosystems and core update processes, allowing attackers to execute arbitrary code or bypass authentication. While the flat-file structure offers performance benefits, it has also introduced unique attack vectors related to file permissions and serialization. Users must prioritize rigorous plugin auditing and timely patching to mitigate these persistent threats inherent in the system’s evolving codebase.

Found 11 results / 187 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-86196 Grav API Plugin before 1.0.20 Authentication Bypass via Host Header — grav-plugin-api CWE-290 8.7 High 2026-09-05
CVE-2026-86195 grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag — grav-plugin-api CWE-269 8.7 High 2026-09-05
CVE-2026-86193 Grav API Plugin Authentication Bypass via Group-Inherited Super — grav-plugin-api CWE-863 8.7 High 2026-09-05
CVE-2026-64852 Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account — grav-plugin-api CWE-862 8.7 High 2026-08-19
CVE-2026-63408 Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter — grav-plugin-api CWE-598 7.5 High 2026-08-19
CVE-2026-63407 Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses — grav-plugin-api CWE-942 8.2 High 2026-08-19
CVE-2026-62667 Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL — grav-plugin-api CWE-862 8.1 High 2026-08-19
CVE-2026-62666 Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super — grav-plugin-api CWE-639 8.8 High 2026-08-19
CVE-2026-61607 Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer — grav-plugin-api CWE-79 4.6 Medium 2026-08-19
CVE-2026-72833 Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys — grav-plugin-api CWE-269 8.8 High 2026-08-14
CVE-2026-42843 grav-plugin-api: Grav API Privilege Escalation to Super Admin — grav-plugin-api CWE-863 8.8 High 2026-05-11

This page lists every published CVE security advisory associated with getgrav. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.