Getgrav
Getgrav Grav: vulnerabilidades y CVE
Getgrav Grav tiene 128 vulnerabilidades publicadas, 100 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE128
Últimos 12 meses100
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100671 | Alta (8.6) | 0.29% | — | 26 sept 2026 | Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission… |
| CVE-2026-100669 | Alta (8.7) | 0.44% | — | 26 sept 2026 | Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts,… |
| CVE-2026-100668 | Alta (7.1) | 0.28% | — | 26 sept 2026 | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r,… |
| CVE-2026-92917 | Alta (8.7) | 0.46% | — | 17 sept 2026 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string):… |
| CVE-2026-92916 | Alta (8.7) | 0.50% | — | 17 sept 2026 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed… |
| CVE-2025-64059 | Baja (1.8) | 0.30% | — | 13 sept 2026 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other… |
| CVE-2026-86197 | Media (5.1) | 0.41% | — | 5 sept 2026 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject… |
| CVE-2026-86196 | Alta (8.7) | 0.43% | — | 5 sept 2026 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled… |
| CVE-2026-85604 | Alta (8.7) | 0.86% | — | 4 sept 2026 | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so… |
| CVE-2026-85603 | Alta (7.1) | 0.63% | — | 4 sept 2026 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission… |
| CVE-2026-85601 | Media (5.1) | 0.28% | — | 4 sept 2026 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI… |
| CVE-2026-85598 | Media (5.1) | 0.26% | — | 4 sept 2026 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular… |
| CVE-2026-76846 | Alta (8.7) | 0.41% | — | 25 ago 2026 | Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or… |
| CVE-2026-76839 | Alta (8.7) | 0.47% | — | 25 ago 2026 | Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call… |
| CVE-2026-72700 | Alta (8.7) | 0.43% | — | 25 ago 2026 | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in… |
| CVE-2026-72698 | Alta (7.1) | 0.41% | — | 25 ago 2026 | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can… |
| CVE-2026-72697 | Alta (7.1) | 0.46% | — | 25 ago 2026 | Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended… |
| CVE-2026-72696 | Alta (8.6) | 0.20% | — | 25 ago 2026 | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in… |
| CVE-2026-72695 | Alta (7.1) | 0.90% | — | 25 ago 2026 | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with… |
| CVE-2026-56710 | Crítica (9.3) | 0.51% | — | 25 ago 2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters… |
| CVE-2026-56709 | Alta (8.7) | 0.43% | — | 25 ago 2026 | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and… |
| CVE-2026-64852 | Alta (8.7) | 0.41% | — | 19 ago 2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in… |
| CVE-2026-64850 | Alta (8.7) | 0.47% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array()… |
| CVE-2026-62673 | Alta (8.2) | 0.54% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns… |
| CVE-2026-62672 | Media (6) | 0.38% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to… |
| CVE-2026-61842 | Media (6.5) | 0.44% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters… |
| CVE-2026-61690 | Media (6.5) | 0.53% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive… |
| CVE-2026-53654 | Media (5.3) | 0.53% | — | 19 ago 2026 | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or… |
| CVE-2026-75837 | Crítica (9.3) | 0.49% | — | 18 ago 2026 | Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to… |
| CVE-2026-75836 | Alta (8.7) | 0.47% | — | 18 ago 2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.