Getgrav
Getgrav Grav-plugin-admin: vulnerabilidades y CVE
Getgrav Grav-plugin-admin tiene 11 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-59190 | Alta (8.7) | 0.36% | — | 10 jul 2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any… |
| CVE-2026-44737 | Media (6.2) | 0.43% | — | 11 may 2026 | grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly… |
| CVE-2025-66310 | Media (6.2) | 0.21% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was… |
| CVE-2025-66309 | Media (6.2) | 0.23% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was… |
| CVE-2025-66308 | Media (6.8) | 0.21% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was… |
| CVE-2025-66312 | Media (6.2) | 0.21% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was… |
| CVE-2025-66311 | Media (6.2) | 0.21% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was… |
| CVE-2025-66307 | Media (5.3) | 0.32% | — | 1 dic 2025 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability… |
| CVE-2021-3920 | Media (5.4) | 1.4% | — | 19 nov 2021 | grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3799 | Media (5.4) | 1.6% | — | 27 sept 2021 | grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames |
| CVE-2021-21425 | Crítica (9.8) | 81% | — | 7 abr 2021 | Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.