Vulnerabilities in Getgrav

187 results
Vexday analysis

Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.

CVE-2026-44737MEDIUMgrav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][title]EPSS 0.4%CVE-2026-56709HIGHGrav before 3.9.2 Host Header Injection via sendInvitationEmailEPSS 0.4%CVE-2026-62386HIGHGrav < 1.0.0-rc.16 Authentication Bypass via token URL ParameterEPSS 0.4%CVE-2026-74907HIGHGrav before 2.0.15 Path Traversal via plugin-asset-map.phpEPSS 0.4%CVE-2026-72700HIGHGrav before 3.9.1 Timing Attack via Non-Constant-Time Token ComparisonEPSS 0.4%CVE-2026-61451CRITICALGrav before 1.0.4 Password Reset Token Poisoning via admin_base_urlEPSS 0.4%CVE-2026-64852HIGHGrav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any accountEPSS 0.4%CVE-2026-62667HIGHGrav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACLEPSS 0.4%CVE-2026-86197MEDIUMGrav before 2.0.20 Cross-Site Scripting via Assets SandboxEPSS 0.4%CVE-2025-66304MEDIUMGrav Exposes Password Hashes Leading to privilege escalationEPSS 0.4%CVE-2026-61450HIGHGrav before 2.0.2 Config Exfiltration via offsetGet FilterEPSS 0.4%CVE-2026-76846HIGHGrav before 2.0.16 Information Disclosure via Twig SandboxEPSS 0.4%CVE-2026-72698HIGHGrav CMS before 2.0.16 Information Disclosure via Twig Sandbox BypassEPSS 0.4%CVE-2026-69088HIGHGrav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via BlueprintEPSS 0.4%CVE-2026-75829HIGHgrav-plugin-api before 1.0.15 Twig SSTI via translate endpointEPSS 0.4%CVE-2026-42610MEDIUMGrav: Sensitive Information Disclosure via Accounts Service BypassEPSS 0.4%CVE-2026-62234HIGHGrav < 2.0.4 SSRF via Unrestricted cURL ProtocolsEPSS 0.4%CVE-2026-75830HIGHgrav-plugin-api before 1.0.15 Path Traversal via batchCopyEPSS 0.4%CVE-2026-44738HIGHGrav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()EPSS 0.4%CVE-2026-75828CRITICALGrav before 2.0.15 Stored XSS via detectXss() Quote BypassEPSS 0.4%