Vulnerabilities in getgrav

180 results
Vexday analysis

O ecossistema de vulnerabilidades do Grav CMS acumula 59 CVEs catalogadas, com 5 classificadas como críticas e 4 contando com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros confirmados no catálogo CISA KEV, cuja taxa permanece abaixo da média geral. A CVE mais preocupante no momento é CVE-2021-21425, com EPSS de 0,8047, indicando alta probabilidade estimada de exploração ativa, o que merece atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O volume de 14 novas CVEs nos últimos 90 dias aponta para uma cadência de descobertas elevada, sugerindo que a superfície de ataque do produto segue em expansão recente. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado em triagens mas que, combinado com PoCs públicas, representa vetor relevante para comprometimento de sessões e escalada de impacto.

CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.6%CVE-2021-3904MEDIUMCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 0.6%CVE-2023-34452MEDIUMGrav vulnerable to Self Cross Site Scripting in /forgot_passwordEPSS 0.6%CVE-2026-72695HIGHGrav before 2.0.16 Path Traversal via MediaUploadTrait deleteFileEPSS 0.6%CVE-2025-66295HIGHGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionEPSS 0.6%CVE-2026-58492CRITICALgrav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name InterpolationEPSS 0.5%CVE-2026-53653HIGHGrav: Unauthenticated denial of service via unbounded image derivative dimensionsEPSS 0.5%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2026-42608HIGHGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.EPSS 0.5%CVE-2026-72819HIGHGrav CMS before 2.0.13 Remote Code Execution via ZIP UploadEPSS 0.5%CVE-2026-58493MEDIUMgrav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String ConstructionEPSS 0.5%CVE-2026-62673HIGHGrav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsEPSS 0.5%CVE-2026-53654MEDIUMGrav: Unauthenticated open redirect via login twofa_cancel _redirectEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-62230HIGHGrav < 2.0.4 File Access Bypass via Case VariationEPSS 0.5%CVE-2026-85604HIGHGrav before 2.0.18 Remote Code Execution via sort filterEPSS 0.5%CVE-2026-65896HIGHGrav API Plugin before 1.0.10 Path Traversal via moveEPSS 0.5%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.5%CVE-2026-61873HIGHGrav before 9.1.8 Arbitrary File Write via Twig-Processed FilenameEPSS 0.5%CVE-2026-62232CRITICALGrav < 2.0.4 2FA Bypass via Secret RegenerationEPSS 0.5%