Vulnerabilities in Getgrav

102 results
Vexday analysis

Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.

CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-61457MEDIUMGrav before 1.0.3 Remote Code Execution via File Upload Extension BypassEPSS 0.5%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.5%CVE-2025-66300HIGHGrav is vulnerable to Arbitrary File ReadEPSS 0.4%CVE-2026-42841MEDIUMGrav: Stored XSS via Markdown media attribute() action in Grav CMSEPSS 0.4%CVE-2025-66304MEDIUMGrav Exposes Password Hashes Leading to privilege escalationEPSS 0.4%CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2025-66305MEDIUMGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterEPSS 0.4%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.4%CVE-2025-66298HIGHGrav is vulnerable to Server-Side Template Injection (SSTI) via FormsEPSS 0.4%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.4%CVE-2026-42843HIGHgrav-plugin-api: Grav API Privilege Escalation to Super AdminEPSS 0.4%CVE-2026-42844HIGHGrav: Low-privileged API users can create super-admin accounts via blueprint-uploadEPSS 0.3%CVE-2025-66296HIGHGrav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account TakeoverEPSS 0.3%CVE-2025-66307MEDIUMGrav Admin Plugin vulnerable to User Enumeration & Email DisclosureEPSS 0.3%CVE-2026-65603HIGHGrav Login Plugin 3.8.11 Privilege Escalation via Profile UpdateEPSS 0.3%CVE-2026-58492CRITICALgrav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name InterpolationEPSS 0.3%CVE-2026-53653HIGHGrav: Unauthenticated denial of service via unbounded image derivative dimensionsEPSS 0.3%CVE-2026-42611HIGHGrav: Stored XSS via Tag InjectionEPSS 0.3%