Vulnerabilities in Getgrav

187 results
Vexday analysis

Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.

CVE-2024-28119HIGHGrav vulnerable to Server Side Template Injection (SSTI) via Twig escape handlerEPSS 1.6%CVE-2022-1173HIGHstored xss in getgrav/gravEPSS 1.5%CVE-2022-0268MEDIUMCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 1.4%CVE-2024-28117HIGHGrav vulnerable to Server Side Template Injection (SSTI)EPSS 1.4%CVE-2021-3920MEDIUMCross-site Scripting (XSS) - Stored in getgrav/grav-plugin-adminEPSS 1.4%CVE-2022-0743MEDIUMCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 1.4%CVE-2024-27923HIGHRemote Code Execution by uploading a phar file using frontmatterEPSS 1.4%CVE-2025-66301HIGHGrav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actionsEPSS 1.3%CVE-2026-65608HIGHGrav before 2.0.9 Remote Code Execution via FlexDirectoryEPSS 1.3%CVE-2024-28118HIGHGrav vulnerable to Server Side Template Injection (SSTI)EPSS 1.2%CVE-2026-58655HIGHGrav Flex Objects - Server-Side Template Injection via Dynamic TitlesEPSS 1.1%CVE-2026-72819HIGHGrav CMS before 2.0.13 Remote Code Execution via ZIP UploadEPSS 0.9%CVE-2026-72695HIGHGrav before 2.0.16 Path Traversal via MediaUploadTrait deleteFileEPSS 0.9%CVE-2026-85604HIGHGrav before 2.0.18 Remote Code Execution via sort filterEPSS 0.9%CVE-2026-75827CRITICALGrav before 2.0.15 Arbitrary File Write via error_logEPSS 0.9%CVE-2026-72827HIGHGrav CMS before 2.0.13 Remote Code Execution via TwigEPSS 0.9%CVE-2026-61457MEDIUMGrav before 1.0.3 Remote Code Execution via File Upload Extension BypassEPSS 0.8%CVE-2025-66297HIGHGrav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig InjectionEPSS 0.8%CVE-2026-72830HIGHGrav API Plugin before 1.0.13 RCE via ConfigController scope bypassEPSS 0.7%CVE-2026-72824HIGHGrav before 1.0.13 API Key Scope Bypass via PagesControllerEPSS 0.7%