Vulnerabilidades em Getgrav
187 resultadosAnálise Vexday
Getgrav possui 2 vulnerabilidades registradas, sendo 1 de criticidade alta (CVSS crítico), ambas relacionadas a Cross-Site Scripting (CWE-79). Nenhuma das falhas está sob exploração ativa documentada e todas antecedem os últimos 90 dias, indicando risco legado sem pressão imediata de ataque.
CVE-2026-85601MEDIUMGrav Admin before 2.0.20 Cross-Site Scripting via marked.jsEPSS 0.3%CVE-2026-42612HIGHGrav: Publisher-Level Stored XSS via Unquoted Event AttributesEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%CVE-2026-85599MEDIUMGrav Shortcode Core before 6.2.5 Stored XSS via unescaped parametersEPSS 0.3%CVE-2026-61453MEDIUMGrav before 2.0.1 XSS via Twig String ConcatenationEPSS 0.3%CVE-2026-42841MEDIUMGrav: Stored XSS via Markdown media attribute() action in Grav CMSEPSS 0.3%CVE-2026-85598MEDIUMGrav 2.0.0 through 2.0.17 Stored XSS via Modular PagesEPSS 0.3%CVE-2026-75834MEDIUMGrav before 2.0.14 Stored XSS via Invalid UTF-8 ByteEPSS 0.3%CVE-2026-42842MEDIUMgrav-plugin-form: XSS via Taxonomy Field Values in Admin PanelEPSS 0.3%CVE-2026-74908MEDIUMGrav plugin-api before 1.0.15 Script Injection via SVGEPSS 0.3%CVE-2026-64628MEDIUMGrav Stored Cross-Site Scripting via Shortcode Attribute HandlersEPSS 0.3%CVE-2026-80204CRITICALGrav before 1.0.18 Authentication Bypass via Scoped API KeyEPSS 0.2%CVE-2026-66400MEDIUMGrav Login Plugin before 3.8.13 Insufficient Session ExpirationEPSS 0.2%CVE-2026-75107MEDIUMGrav Form Plugin before 9.1.19 Stored XSS via Field PropertiesEPSS 0.2%CVE-2026-61456MEDIUMGrav before 1.0.3 Stored XSS via SVG Upload APIEPSS 0.2%CVE-2026-85600MEDIUMGrav Admin before 2.0.21 Stored XSS via usernameEPSS 0.2%CVE-2026-72821MEDIUMGrav Form Plugin before 9.1.15 Stored XSS via Radio ToggleEPSS 0.2%CVE-2025-66309MEDIUMGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tabEPSS 0.2%CVE-2026-75833HIGHGrav API Plugin Open Redirect via Backslash BypassEPSS 0.2%CVE-2025-66308MEDIUMGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`EPSS 0.2%