Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.30% | — | Getgrav Grav CMSAI | 26/9/2026 | 30/9/2026 | Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested… | |
| Aplazada | Crítica (9.3) | 0.15% | — | Getgrav Grav CMSAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim… | |
| Aplazada | Media (6.3) | 0.28% | — | Getgrav Grav CMSAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests,… | |
| Aplazada | Alta (7.5) | 0.49% | — | Grav API PluginAIGetgrav Grav CMSAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Request URLs… | |
| Aplazada | Alta (8.7) | 0.85% | — | Getgrav Grav CMSAI | 14/8/2026 | 8/9/2026 | Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig payloads using the unsandboxed find filter in email subject, body, to, or from fields to achieve… | |
| Modificada | Alta (8.8) | 1.4% | — | Getgrav Grav CMS | 15/3/2021 | 17/6/2026 | The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF). | |
| Modificada | Media (5.5) | 0.98% | — | Getgrav Grav CMS | 15/3/2021 | 17/6/2026 | The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.) | |
| Modificada | Alta (8.1) | 2.9% | — | Getgrav Grav CMS | 15/3/2021 | 17/6/2026 | The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSRF protection.) | |
| Modificada | Media (6.1) | 1.5% | — | Getgrav Grav CMS | 9/9/2019 | 17/6/2026 | Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images. | |
| Modificada | Media (6.1) | 3.3% | — | Getgrav Grav CMS | 19/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools. |