Vulnerabilidades em Getgrav

187 resultados
Análise Vexday

Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.

CVE-2026-75574HIGHGrav before 4.2.2 Remote Code Execution via Email TwigEPSS 0.7%CVE-2020-36955MEDIUMGrav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site ScriptingEPSS 0.6%CVE-2026-62666HIGHGrav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of superEPSS 0.6%CVE-2026-85603HIGHGrav Admin Plugin Path Traversal via Save As Language CodeEPSS 0.6%CVE-2025-66299HIGHSecurity Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMSEPSS 0.6%CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.6%CVE-2023-34452MEDIUMGrav vulnerable to Self Cross Site Scripting in /forgot_passwordEPSS 0.6%CVE-2021-3904MEDIUMCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 0.6%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.6%CVE-2026-86194MEDIUMGrav Form Plugin before 9.1.22 Cross-Page Form ExecutionEPSS 0.6%CVE-2026-72831HIGHGrav through 2.0.11 Authentication Bypass via Flex ObjectsEPSS 0.6%CVE-2026-42613CRITICALGrav: Privilege Escalation via Missing Server-Side Validation of groups/accessEPSS 0.6%CVE-2026-72822HIGHGrav before 1.0.13 Authentication Bypass via disable2faEPSS 0.6%CVE-2025-66295HIGHGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionEPSS 0.6%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.5%CVE-2026-62673HIGHGrav: .htaccess file extension rules bypass via case variation on case-insensitive filesystemsEPSS 0.5%CVE-2026-61690MEDIUMGrav: Decompression Bomb via ZipArchiver - Missing Extraction LimitsEPSS 0.5%CVE-2026-53654MEDIUMGrav: Unauthenticated open redirect via login twofa_cancel _redirectEPSS 0.5%CVE-2026-58492CRITICALgrav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name InterpolationEPSS 0.5%CVE-2026-53653HIGHGrav: Unauthenticated denial of service via unbounded image derivative dimensionsEPSS 0.5%