Exposure of Grav

CMS
247
exposure score
771
sites use
0
exploited
18
critical
Vexday analysis

O CMS Grav acumula 46 CVEs catalogadas, com 13 surgidas nos últimos 90 dias — volume recente que indica atenção contínua da comunidade de pesquisa à superfície de ataque da plataforma. Nenhuma vulnerabilidade consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, o que sugere ausência de exploração ativa confirmada até o momento, embora isso não elimine o risco. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão recorrente em aplicações de gerenciamento de conteúdo. A CVE mais preocupante no cenário atual é CVE-2024-27921, com EPSS de aproximadamente 0,61, indicando probabilidade relevante de exploração — equipes responsáveis por instâncias Grav devem priorizá-la nas verificações de atualização, especialmente considerando que há 3 CVEs de severidade crítica no portfólio total.

CVEs

150 results
CVE-2026-42612HIGHGrav: Publisher-Level Stored XSS via Unquoted Event AttributesEPSS 0.2%CVE-2026-61456MEDIUMGrav before 1.0.3 Stored XSS via SVG Upload APIEPSS 0.2%CVE-2026-69088HIGHGrav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via BlueprintEPSS 0.2%CVE-2025-64059LOWGrav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admEPSS 0.2%CVE-2025-66309MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tabEPSS 0.2%CVE-2026-75835CRITICALGrav API Plugin before 1.0.14 Missing AuthorizationEPSS 0.2%CVE-2026-75832CRITICALGrav API Plugin before 1.0.14 Authorization BypassEPSS 0.2%CVE-2026-56707HIGHGrav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via ShortcodeEPSS 0.2%CVE-2025-66308MEDIUMGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`EPSS 0.2%CVE-2025-66312MEDIUMGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`EPSS 0.2%CVE-2025-66311MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parametersEPSS 0.2%CVE-2025-66310MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced TabEPSS 0.2%CVE-2026-75833HIGHGrav API Plugin Open Redirect via Backslash BypassEPSS 0.2%CVE-2026-72823MEDIUMGrav before 1.0.13 API-key scope cap bypass via DemoControllerEPSS 0.2%CVE-2026-75834MEDIUMGrav before 2.0.14 Stored XSS via Invalid UTF-8 ByteEPSS 0.2%CVE-2026-74908MEDIUMGrav plugin-api before 1.0.15 Script Injection via SVGEPSS 0.2%CVE-2026-72832MEDIUMGrav before 2.0.12 Stored XSS via quoted-attribute bypassEPSS 0.2%CVE-2026-72701MEDIUMGrav CMS before 2.0.16 Timing Attack via verifyNonceEPSS 0.2%CVE-2026-56708MEDIUMGrav API Plugin before 1.0.16 SSRF via DNS RebindingEPSS 0.2%CVE-2026-75107MEDIUMGrav Form Plugin before 9.1.19 Stored XSS via Field PropertiesEPSS 0.2%