VendorsGetgravgravall versions
Vulnerabilities

Getgrav Grav

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2024-34082
Grav Arbitrary File Read to Account Takeover
Published 2024-05-15 · Analyzed
9.9EPSS 0.030
CVE-2023-34251
Grav Server Side Template Injection vulnerability
Published 2023-06-14 · Modified
9.9EPSS 0.023
CVE-2021-47812
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
Published 2026-01-15 · Modified
9.8EPSS 0.022
CVE-2025-46199
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields
Published 2025-07-25 · Analyzed
9.8EPSS 0.008
CVE-2025-66301
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
Published 2025-12-01 · Analyzed
9.6EPSS 0.013
CVE-2022-2073
Code Injection in getgrav/grav
Published 2022-06-29 · Modified
9.1EPSS 0.109
CVE-2026-42608
Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
Published 2026-05-11 · Analyzed
9.1EPSS 0.006
CVE-2025-66844
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered
Published 2025-12-15 · Analyzed
9.1EPSS 0.003
CVE-2026-42611
Grav: Stored XSS via Tag Injection
Published 2026-05-11 · Analyzed
8.9EPSS 0.004
CVE-2024-27921
Grav File Upload Path Traversal vulnerability
Published 2024-03-21 · Analyzed
8.8EPSS 0.606
CVE-2024-28116
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
Published 2024-03-21 · Analyzed
8.8EPSS 0.058
CVE-2023-34448
Grav Server-side Template Injection (SSTI) via Twig Default Filters
Published 2023-06-14 · Modified
8.8EPSS 0.045
CVE-2021-3924
Path Traversal in getgrav/grav
Published 2021-11-05 · Modified
8.8EPSS 0.044
CVE-2025-66294
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
Published 2025-12-01 · Analyzed
8.8EPSS 0.028
CVE-2023-37897
Server-side Template Injection (SSTI) in grav
Published 2023-07-18 · Modified
8.8EPSS 0.028
CVE-2023-34253
Grav vulnerable to Server-side Template Injection (SSTI) via Denylist Bypass
Published 2023-06-14 · Modified
8.8EPSS 0.021
CVE-2023-34252
Grav Server-side Template Injection via Insufficient Validation in filterFilter
Published 2023-06-14 · Modified
8.8EPSS 0.021
CVE-2024-28119
Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handler
Published 2024-03-21 · Analyzed
8.8EPSS 0.016
CVE-2024-28117
Grav vulnerable to Server Side Template Injection (SSTI)
Published 2024-03-21 · Analyzed
8.8EPSS 0.014
CVE-2024-27923
Remote Code Execution by uploading a phar file using frontmatter
Published 2024-03-06 · Analyzed
8.8EPSS 0.014
CVE-2024-28118
Grav vulnerable to Server Side Template Injection (SSTI)
Published 2024-03-21 · Analyzed
8.8EPSS 0.012
CVE-2025-66297
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
Published 2025-12-01 · Analyzed
8.8EPSS 0.008
CVE-2025-46198
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attribute of the img element
Published 2025-07-25 · Analyzed
8.8EPSS 0.006
CVE-2025-66299
Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
Published 2025-12-01 · Analyzed
8.8EPSS 0.006
CVE-2025-66295
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
Published 2025-12-01 · Analyzed
8.8EPSS 0.006
CVE-2026-42844
Grav: Low-privileged API users can create super-admin accounts via blueprint-upload
Published 2026-05-12 · Analyzed
8.8EPSS 0.005
CVE-2025-66296
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
Published 2025-12-01 · Analyzed
8.8EPSS 0.003
CVE-2025-66300
Grav is vulnerable to Arbitrary File Read
Published 2025-12-01 · Analyzed
8.5EPSS 0.005
CVE-2026-42612
Grav: Publisher-Level Stored XSS via Unquoted Event Attributes
Published 2026-05-11 · Analyzed
8.5EPSS 0.003
CVE-2021-29440
Twig allowing dangerous PHP functions by default
Published 2021-04-13 · Modified
8.41 PoCEPSS 0.306
CVE-2022-1173
stored xss in getgrav/grav
Published 2022-04-26 · Modified
8.2EPSS 0.015
CVE-2025-50286
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploaded, the plugin is automatically extracted and loaded, allowing arbitrary PHP code execution and reverse shell access.
Published 2025-08-06 · Analyzed
8.11 PoCEPSS 0.096
CVE-2026-42609
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
Published 2026-05-11 · Modified
8.1EPSS 0.006
CVE-2026-44738
Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()
Published 2026-05-11 · Modified
7.7EPSS 0.004
CVE-2025-66298
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
Published 2025-12-01 · Analyzed
7.7EPSS 0.004
CVE-2026-29924
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
Published 2026-03-30 · Analyzed
7.6EPSS 0.003
CVE-2025-66304
Grav Exposes Password Hashes Leading to privilege escalation
Published 2025-12-01 · Analyzed
7.2EPSS 0.004
CVE-2022-0970
Cross-site Scripting (XSS) - Stored in getgrav/grav
Published 2022-03-15 · Modified
7.1EPSS 0.018
CVE-2026-59193
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
Published 2026-07-10 · Modified
6.9EPSS 0.006
CVE-2025-66305
Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
Published 2025-12-01 · Analyzed
6.9EPSS 0.004
1 / 2Next →