Vulnerabilities in getgrav

180 results
Vexday analysis

O ecossistema de vulnerabilidades do Grav CMS acumula 59 CVEs catalogadas, com 5 classificadas como críticas e 4 contando com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros confirmados no catálogo CISA KEV, cuja taxa permanece abaixo da média geral. A CVE mais preocupante no momento é CVE-2021-21425, com EPSS de 0,8047, indicando alta probabilidade estimada de exploração ativa, o que merece atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O volume de 14 novas CVEs nos últimos 90 dias aponta para uma cadência de descobertas elevada, sugerindo que a superfície de ataque do produto segue em expansão recente. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado em triagens mas que, combinado com PoCs públicas, representa vetor relevante para comprometimento de sessões e escalada de impacto.

CVE-2026-72825HIGHGrav before 1.0.13 API-key scope cap bypass via ReportsControllerEPSS 0.2%CVE-2026-62670MEDIUMFail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny)EPSS 0.2%CVE-2026-72698HIGHGrav CMS before 2.0.16 Information Disclosure via Twig Sandbox BypassEPSS 0.2%CVE-2026-76846HIGHGrav before 2.0.16 Information Disclosure via Twig SandboxEPSS 0.2%CVE-2026-42612HIGHGrav: Publisher-Level Stored XSS via Unquoted Event AttributesEPSS 0.2%CVE-2026-61456MEDIUMGrav before 1.0.3 Stored XSS via SVG Upload APIEPSS 0.2%CVE-2026-69088HIGHGrav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via BlueprintEPSS 0.2%CVE-2025-64059LOWGrav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admEPSS 0.2%CVE-2025-66309MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tabEPSS 0.2%CVE-2026-86195HIGHgrav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super FlagEPSS 0.2%CVE-2026-75835CRITICALGrav API Plugin before 1.0.14 Missing AuthorizationEPSS 0.2%CVE-2026-75832CRITICALGrav API Plugin before 1.0.14 Authorization BypassEPSS 0.2%CVE-2026-56707HIGHGrav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via ShortcodeEPSS 0.2%CVE-2026-86193HIGHGrav API Plugin Authentication Bypass via Group-Inherited SuperEPSS 0.2%CVE-2025-66310MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced TabEPSS 0.2%CVE-2025-66311MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parametersEPSS 0.2%CVE-2025-66308MEDIUMGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`EPSS 0.2%CVE-2025-66312MEDIUMGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`EPSS 0.2%CVE-2026-72699CRITICALGrav Login Plugin before 3.9.1 Email Enumeration via RegistrationEPSS 0.2%CVE-2026-75833HIGHGrav API Plugin Open Redirect via Backslash BypassEPSS 0.2%