« Volver al listado

Getgrav

Getgrav Grav: vulnerabilidades y CVE

Getgrav Grav tiene 128 vulnerabilidades publicadas, 100 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE128
Últimos 12 meses100
Críticas14
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100671Alta (8.6)0.29%—26 sept 2026
Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission…
CVE-2026-100669Alta (8.7)0.44%—26 sept 2026
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts,…
CVE-2026-100668Alta (7.1)0.28%—26 sept 2026
Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r,…
CVE-2026-92917Alta (8.7)0.46%—17 sept 2026
Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string):…
CVE-2026-92916Alta (8.7)0.50%—17 sept 2026
Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed…
CVE-2025-64059Baja (1.8)0.30%—13 sept 2026
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other…
CVE-2026-86197Media (5.1)0.41%—5 sept 2026
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject…
CVE-2026-86196Alta (8.7)0.43%—5 sept 2026
Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled…
CVE-2026-85604Alta (8.7)0.86%—4 sept 2026
Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so…
CVE-2026-85603Alta (7.1)0.63%—4 sept 2026
Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission…
CVE-2026-85601Media (5.1)0.28%—4 sept 2026
Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI…
CVE-2026-85598Media (5.1)0.26%—4 sept 2026
Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular…
CVE-2026-76846Alta (8.7)0.41%—25 ago 2026
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or…
CVE-2026-76839Alta (8.7)0.47%—25 ago 2026
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call…
CVE-2026-72700Alta (8.7)0.43%—25 ago 2026
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in…
CVE-2026-72698Alta (7.1)0.41%—25 ago 2026
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can…
CVE-2026-72697Alta (7.1)0.46%—25 ago 2026
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended…
CVE-2026-72696Alta (8.6)0.20%—25 ago 2026
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in…
CVE-2026-72695Alta (7.1)0.90%—25 ago 2026
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with…
CVE-2026-56710Crítica (9.3)0.51%—25 ago 2026
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters…
CVE-2026-56709Alta (8.7)0.43%—25 ago 2026
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and…
CVE-2026-64852Alta (8.7)0.41%—19 ago 2026
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in…
CVE-2026-64850Alta (8.7)0.47%—19 ago 2026
Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array()…
CVE-2026-62673Alta (8.2)0.54%—19 ago 2026
Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns…
CVE-2026-62672Media (6)0.38%—19 ago 2026
Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to…
CVE-2026-61842Media (6.5)0.44%—19 ago 2026
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters…
CVE-2026-61690Media (6.5)0.53%—19 ago 2026
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive…
CVE-2026-53654Media (5.3)0.53%—19 ago 2026
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or…
CVE-2026-75837Crítica (9.3)0.49%—18 ago 2026
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to…
CVE-2026-75836Alta (8.7)0.47%—18 ago 2026
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services31
  2. T1190 Exploit Public-Facing Application28
  3. T1005 Data from Local System20
  4. T1059 Command and Scripting Interpreter14
  5. T1078 Valid Accounts6
  6. T1068 Exploitation for Privilege Escalation4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Getgrav