Vulnerabilities in Getgrav
187 resultsVexday analysis
Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.
CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2026-42608HIGHGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.EPSS 0.5%CVE-2026-80203CRITICALGrav before 1.0.18 Authentication Bypass via Scoped API KeyEPSS 0.5%CVE-2026-56710CRITICALGrav Login Plugin before 1.0.16 Privilege Escalation via UnlockEPSS 0.5%CVE-2026-62669HIGHGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeEPSS 0.5%CVE-2026-58493MEDIUMgrav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String ConstructionEPSS 0.5%CVE-2026-92916HIGHGrav through 2.0.21 Unauthenticated Information Disclosure via ClockworkEPSS 0.5%CVE-2026-72820MEDIUMGrav 2.0.11 Path Traversal via Backup Profile ConfigurationEPSS 0.5%CVE-2026-75837CRITICALGrav before 2.0.14 Privilege Escalation via Group Access FieldEPSS 0.5%CVE-2026-63408HIGHGrav API Plugin: JWT Access Token Accepted via `?token=` URL Query ParameterEPSS 0.5%CVE-2026-72828HIGHGrav before 1.0.13 API Key Scope Bypass via InvitationsControllerEPSS 0.5%CVE-2026-42843HIGHgrav-plugin-api: Grav API Privilege Escalation to Super AdminEPSS 0.5%CVE-2026-42844HIGHGrav: Low-privileged API users can create super-admin accounts via blueprint-uploadEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-62230HIGHGrav < 2.0.4 File Access Bypass via Case VariationEPSS 0.5%CVE-2026-65896HIGHGrav API Plugin before 1.0.10 Path Traversal via moveEPSS 0.5%CVE-2026-72826HIGHGrav before 1.0.13 Scope Bypass via createApiKeyEPSS 0.5%CVE-2026-72829HIGHGrav before 1.0.13 API Key Scope Bypass via UsersControllerEPSS 0.5%CVE-2026-72833HIGHGrav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API KeysEPSS 0.5%CVE-2026-75836HIGHGrav API Plugin before 1.0.14 Missing AuthorizationEPSS 0.5%