Getgrav
Getgrav Grav CMS: vulnerabilidades y CVE
Getgrav Grav CMS tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100670 | Alta (8.7) | 0.30% | — | 26 sept 2026 | Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path,… |
| CVE-2026-72702 | Crítica (9.3) | 0.15% | — | 25 ago 2026 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match… |
| CVE-2026-72701 | Media (6.3) | 0.28% | — | 25 ago 2026 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can… |
| CVE-2026-63408 | Alta (7.5) | 0.49% | — | 19 ago 2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL… |
| CVE-2026-72827 | Alta (8.7) | 0.85% | — | 14 ago 2026 | Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to execute arbitrary operating-system commands. Attackers can inject Twig… |
| CVE-2020-29553 | Alta (8.8) | 1.4% | — | 15 mar 2021 | The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF). |
| CVE-2020-29556 | Media (5.5) | 0.98% | — | 15 mar 2021 | The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be… |
| CVE-2020-29555 | Alta (8.1) | 2.9% | — | 15 mar 2021 | The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also… |
| CVE-2019-16126 | Media (6.1) | 1.5% | — | 9 sept 2019 | Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images. |
| CVE-2018-5233 | Media (6.1) | 3.3% | — | 19 mar 2018 | Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.