Vulnerabilidades en Getgrav

187 resultados
Análisis Vexday

Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.

CVE-2026-65895HIGHGrav API Plugin before 1.0.10 Broken Access ControlEPSS 0.3%CVE-2026-72823MEDIUMGrav before 1.0.13 API-key scope cap bypass via DemoControllerEPSS 0.3%CVE-2026-61452MEDIUMGrav before 2.0.4 Improper Session Invalidation JWT Access TokensEPSS 0.3%CVE-2025-66296HIGHGrav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account TakeoverEPSS 0.3%CVE-2025-66307MEDIUMGrav Admin Plugin vulnerable to User Enumeration & Email DisclosureEPSS 0.3%CVE-2026-72832MEDIUMGrav before 2.0.12 Stored XSS via quoted-attribute bypassEPSS 0.3%CVE-2026-55890MEDIUMGrav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()EPSS 0.3%CVE-2026-75835CRITICALGrav API Plugin before 1.0.14 Missing AuthorizationEPSS 0.3%CVE-2026-100667MEDIUMgrav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication BypassEPSS 0.3%CVE-2026-100670HIGHGrav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard BypassEPSS 0.3%CVE-2025-64059LOWGrav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admEPSS 0.3%CVE-2026-75832CRITICALGrav API Plugin before 1.0.14 Authorization BypassEPSS 0.3%CVE-2025-66306MEDIUMGrav vulnerable to Information Disclosure via IDOR in Grav Admin PanelEPSS 0.3%CVE-2026-100673HIGHGrav Data Manager before 1.4.5 Stored XSS via item-detail viewEPSS 0.3%CVE-2026-100671HIGHGrav before 2.0.25 Session Cookie Theft via Twig SandboxEPSS 0.3%CVE-2026-61607MEDIUMGrav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses SanitizerEPSS 0.3%CVE-2026-62235LOWGrav Flex-Objects < 1.4.3 Authorization Bypass via APIEPSS 0.3%CVE-2026-56708MEDIUMGrav API Plugin before 1.0.16 SSRF via DNS RebindingEPSS 0.3%CVE-2026-72701MEDIUMGrav CMS before 2.0.16 Timing Attack via verifyNonceEPSS 0.3%CVE-2026-100668HIGHGrav before 2.0.25 Sandbox Escape via array FilterEPSS 0.3%