VendorsGetgravgrav1.8.0
Vulnerabilities

Getgrav Grav 1.8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2025-66301
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
Published 2025-12-01 · Analyzed
9.6EPSS 0.013
CVE-2025-66294
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
Published 2025-12-01 · Analyzed
8.8EPSS 0.028
CVE-2025-66297
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
Published 2025-12-01 · Analyzed
8.8EPSS 0.008
CVE-2025-66299
Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
Published 2025-12-01 · Analyzed
8.8EPSS 0.006
CVE-2025-66295
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
Published 2025-12-01 · Analyzed
8.8EPSS 0.006
CVE-2025-66296
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
Published 2025-12-01 · Analyzed
8.8EPSS 0.003
CVE-2025-66300
Grav is vulnerable to Arbitrary File Read
Published 2025-12-01 · Analyzed
8.5EPSS 0.005
CVE-2025-66298
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
Published 2025-12-01 · Analyzed
7.7EPSS 0.004
CVE-2025-66304
Grav Exposes Password Hashes Leading to privilege escalation
Published 2025-12-01 · Analyzed
7.2EPSS 0.004
CVE-2025-66305
Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
Published 2025-12-01 · Analyzed
6.9EPSS 0.004
CVE-2025-66302
Grav vulnerable to Path Traversal allowing server files backup
Published 2025-12-01 · Analyzed
6.8EPSS 0.005
CVE-2025-66306
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Published 2025-12-01 · Analyzed
6.5EPSS 0.003
CVE-2025-66303
Grav is vulnerable to a DOS on the admin panel
Published 2025-12-01 · Analyzed
4.9EPSS 0.004