VendorsGetgravgravany version
Vulnerabilities

Getgrav Grav any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2021-3818
Reliance on Cookies without Validation and Integrity Checking in getgrav/grav
Published 2021-09-27 · Modified
6.3EPSS 0.025
CVE-2021-3904
Cross-site Scripting (XSS) - Stored in getgrav/grav
Published 2021-10-27 · Modified
6.3EPSS 0.006
CVE-2020-11529
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
Published 2020-04-04 · Modified
6.1EPSS 0.109
CVE-2023-34452
Grav vulnerable to Self Cross Site Scripting in /forgot_password
Published 2023-06-14 · Modified
6.1EPSS 0.006
CVE-2022-0268
Cross-site Scripting (XSS) - Stored in getgrav/grav
Published 2022-01-25 · Modified
5.7EPSS 0.014
CVE-2023-31506
A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element.
Published 2024-02-09 · Modified
5.4EPSS 0.010
CVE-2020-37256
Grav - Cross-Site Scripting in Admin Plugin Page Editor
Published 2026-06-25 · Analyzed
5.4EPSS 0.003
CVE-2025-66843
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other user views or edits the affected page.
Published 2025-12-15 · Analyzed
5.4EPSS 0.002
CVE-2025-66303
Grav is vulnerable to a DOS on the admin panel
Published 2025-12-01 · Analyzed
4.9EPSS 0.004
CVE-2022-0743
Cross-site Scripting (XSS) - Stored in getgrav/grav
Published 2022-02-28 · Modified
4.6EPSS 0.014
← Prev2 / 2