Vulnerabilities in getgrav

180 results
Vexday analysis

O ecossistema de vulnerabilidades do Grav CMS acumula 59 CVEs catalogadas, com 5 classificadas como críticas e 4 contando com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros confirmados no catálogo CISA KEV, cuja taxa permanece abaixo da média geral. A CVE mais preocupante no momento é CVE-2021-21425, com EPSS de 0,8047, indicando alta probabilidade estimada de exploração ativa, o que merece atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O volume de 14 novas CVEs nos últimos 90 dias aponta para uma cadência de descobertas elevada, sugerindo que a superfície de ataque do produto segue em expansão recente. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado em triagens mas que, combinado com PoCs públicas, representa vetor relevante para comprometimento de sessões e escalada de impacto.

CVE-2026-80203CRITICALGrav before 1.0.18 Authentication Bypass via Scoped API KeyEPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2026-62672MEDIUMGrav: Authenticated ReDoS via regex_replace in Twig SandboxEPSS 0.4%CVE-2026-62669HIGHGrav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending ChallengeEPSS 0.4%CVE-2025-66305MEDIUMGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterEPSS 0.4%CVE-2026-62231HIGHGrav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticatorEPSS 0.4%CVE-2026-64852HIGHGrav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any accountEPSS 0.4%CVE-2025-66298HIGHGrav is vulnerable to Server-Side Template Injection (SSTI) via FormsEPSS 0.4%CVE-2026-61690MEDIUMGrav: Decompression Bomb via ZipArchiver - Missing Extraction LimitsEPSS 0.4%CVE-2026-62667HIGHGrav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACLEPSS 0.4%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.4%CVE-2026-65007HIGHGrav before 1.0.8 Missing Authorization on API Key GenerationEPSS 0.4%CVE-2026-75574HIGHGrav before 4.2.2 Remote Code Execution via Email TwigEPSS 0.4%CVE-2026-59190HIGHGrav Admin Plugin — IDOR Privilege Escalation via saveUser()EPSS 0.4%CVE-2026-63408HIGHGrav API Plugin: JWT Access Token Accepted via `?token=` URL Query ParameterEPSS 0.4%CVE-2026-61454HIGHGrav before 2.0.4 Information Disclosure via __GRAV_CONFIG__EPSS 0.4%CVE-2026-92916HIGHGrav through 2.0.21 Unauthenticated Information Disclosure via ClockworkEPSS 0.4%CVE-2026-42843HIGHgrav-plugin-api: Grav API Privilege Escalation to Super AdminEPSS 0.4%CVE-2026-75828CRITICALGrav before 2.0.15 Stored XSS via detectXss() Quote BypassEPSS 0.3%CVE-2026-62387HIGHGrav < 1.0.0-rc.16 CORS Misconfiguration via API PluginEPSS 0.3%