Vulnerabilities in Getgrav
187 resultsVexday analysis
Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.
CVE-2026-86195HIGHgrav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super FlagEPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2026-62231HIGHGrav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticatorEPSS 0.4%CVE-2025-66305MEDIUMGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterEPSS 0.4%CVE-2026-62672MEDIUMGrav: Authenticated ReDoS via regex_replace in Twig SandboxEPSS 0.4%CVE-2025-66298HIGHGrav is vulnerable to Server-Side Template Injection (SSTI) via FormsEPSS 0.4%CVE-2026-63407HIGHGrav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API ResponsesEPSS 0.4%CVE-2026-56707HIGHGrav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via ShortcodeEPSS 0.4%CVE-2026-69087HIGHGrav Form Plugin before 9.1.13 Open Redirect via form.value() TwigEPSS 0.4%CVE-2026-65007HIGHGrav before 1.0.8 Missing Authorization on API Key GenerationEPSS 0.4%CVE-2026-86193HIGHGrav API Plugin Authentication Bypass via Group-Inherited SuperEPSS 0.4%CVE-2026-59190HIGHGrav Admin Plugin — IDOR Privilege Escalation via saveUser()EPSS 0.4%CVE-2026-42611HIGHGrav: Stored XSS via Tag InjectionEPSS 0.4%CVE-2026-85602CRITICALGrav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication BypassEPSS 0.4%CVE-2026-61454HIGHGrav before 2.0.4 Information Disclosure via __GRAV_CONFIG__EPSS 0.4%CVE-2026-75831MEDIUMGrav before 2.0.15 Stored XSS via audio/video source URLEPSS 0.4%CVE-2026-72825HIGHGrav before 1.0.13 API-key scope cap bypass via ReportsControllerEPSS 0.3%CVE-2026-72699CRITICALGrav Login Plugin before 3.9.1 Email Enumeration via RegistrationEPSS 0.3%CVE-2026-62387HIGHGrav < 1.0.0-rc.16 CORS Misconfiguration via API PluginEPSS 0.3%CVE-2026-62670MEDIUMFail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny)EPSS 0.3%