Exposição de Grav

CMS
247
score de exposição
771
sites usam
0
em exploração
18
críticos
Análise Vexday

O CMS Grav acumula 46 CVEs catalogadas, com 13 surgidas nos últimos 90 dias — volume recente que indica atenção contínua da comunidade de pesquisa à superfície de ataque da plataforma. Nenhuma vulnerabilidade consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, o que sugere ausência de exploração ativa confirmada até o momento, embora isso não elimine o risco. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão recorrente em aplicações de gerenciamento de conteúdo. A CVE mais preocupante no cenário atual é CVE-2024-27921, com EPSS de aproximadamente 0,61, indicando probabilidade relevante de exploração — equipes responsáveis por instâncias Grav devem priorizá-la nas verificações de atualização, especialmente considerando que há 3 CVEs de severidade crítica no portfólio total.

CVEs

150 resultados
CVE-2026-42613CRITICALGrav: Privilege Escalation via Missing Server-Side Validation of groups/accessEPSS 0.9%CVE-2026-65608HIGHGrav before 2.0.9 Remote Code Execution via FlexDirectoryEPSS 0.8%CVE-2026-61457MEDIUMGrav before 1.0.3 Remote Code Execution via File Upload Extension BypassEPSS 0.8%CVE-2025-66297HIGHGrav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig InjectionEPSS 0.8%CVE-2026-75827CRITICALGrav before 2.0.15 Arbitrary File Write via error_logEPSS 0.8%CVE-2026-72827HIGHGrav CMS before 2.0.13 Remote Code Execution via TwigEPSS 0.6%CVE-2025-66299HIGHSecurity Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMSEPSS 0.6%CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.6%CVE-2023-34452MEDIUMGrav vulnerable to Self Cross Site Scripting in /forgot_passwordEPSS 0.6%CVE-2026-72695HIGHGrav before 2.0.16 Path Traversal via MediaUploadTrait deleteFileEPSS 0.6%CVE-2025-66295HIGHGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionEPSS 0.6%CVE-2026-58492CRITICALgrav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name InterpolationEPSS 0.5%CVE-2026-53653HIGHGrav: Unauthenticated denial of service via unbounded image derivative dimensionsEPSS 0.5%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.5%CVE-2026-42608HIGHGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.EPSS 0.5%CVE-2026-72819HIGHGrav CMS before 2.0.13 Remote Code Execution via ZIP UploadEPSS 0.5%CVE-2026-58493MEDIUMgrav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String ConstructionEPSS 0.5%CVE-2026-62673HIGHGrav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsEPSS 0.5%CVE-2026-53654MEDIUMGrav: Unauthenticated open redirect via login twofa_cancel _redirectEPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%