VendorsGetgravgrav-plugin-adminall versions
Vulnerabilities

Getgrav Grav-plugin-admin

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-21425
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
Published 2021-04-07 · Modified
9.81 PoCEPSS 0.806
CVE-2025-66308
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`
Published 2025-12-01 · Analyzed
6.8EPSS 0.002
CVE-2025-66307
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
Published 2025-12-01 · Analyzed
6.5EPSS 0.003
CVE-2025-66309
Grav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab
Published 2025-12-01 · Analyzed
6.2EPSS 0.002
CVE-2025-66310
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
Published 2025-12-01 · Analyzed
6.2EPSS 0.002
CVE-2025-66311
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
Published 2025-12-01 · Analyzed
6.2EPSS 0.002
CVE-2025-66312
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`
Published 2025-12-01 · Analyzed
6.2EPSS 0.002
CVE-2021-3799
Improper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-admin
Published 2021-09-27 · Modified
5.8EPSS 0.016
CVE-2021-3920
Cross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admin
Published 2021-11-19 · Modified
5.4EPSS 0.014