getgrav
- Total products in the ecosystem
- 7
- Total vulnerabilities (90 days)
- 117
en
Verify to analyze this security profile
As of 09/19/2026, getgrav recorded 117 security vulnerabilities in the last 90 days across 7 products, including 80 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, grav had the most security vulnerabilities in the getgrav ecosystem, with 99 vulnerabilities—approximately 84.62% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-92917Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r | Exploitation statusNot confirmed | FixYes | Affected productgrav | Published09/17/2026 | SeverityHigh |
CVE-2026-92916Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork | Exploitation statusNot confirmed | FixYes | Affected productgrav | Published09/17/2026 | SeverityHigh |
CVE-2025-64059 | Exploitation statusPublic exploit | FixNot confirmed | Affected productgrav | Published09/13/2026 | SeverityLow |
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published09/05/2026 | SeverityMedium |
CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Header | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published09/05/2026 | SeverityHigh |
CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published09/05/2026 | SeverityHigh |
CVE-2026-86194Grav Form Plugin before 9.1.22 Cross-Page Form Execution | Exploitation statusNot known exploited | FixYes | Affected productgrav-plugin-form | Published09/05/2026 | SeverityMedium |
CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Super | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published09/05/2026 | SeverityHigh |
CVE-2026-85604Grav before 2.0.18 Remote Code Execution via sort filter | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published09/04/2026 | SeverityHigh |
CVE-2026-85603Grav Admin Plugin Path Traversal via Save As Language Code | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published09/04/2026 | SeverityHigh |
CVE-2026-85602Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-form | Published09/04/2026 | SeverityCritical |
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.js | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published09/04/2026 | SeverityMedium |
CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via username | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-admin2 | Published09/04/2026 | SeverityMedium |
CVE-2026-85599Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-shortcode-core | Published09/04/2026 | SeverityMedium |
CVE-2026-85598Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published09/04/2026 | SeverityMedium |
CVE-2026-80204Grav before 1.0.18 Authentication Bypass via Scoped API Key | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/26/2026 | SeverityCritical |
CVE-2026-80203Grav before 1.0.18 Authentication Bypass via Scoped API Key | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/26/2026 | SeverityCritical |
CVE-2026-76846Grav before 2.0.16 Information Disclosure via Twig Sandbox | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-76839Grav before 2.0.16 Information Disclosure via offsetGet | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twig | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-72702Grav CMS before 2.0.16 Origin Validation Bypass via Referer | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityCritical |
CVE-2026-72701Grav CMS before 2.0.16 Timing Attack via verifyNonce | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityMedium |
CVE-2026-72700Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-72699Grav Login Plugin before 3.9.1 Email Enumeration via Registration | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-login | Published08/25/2026 | SeverityCritical |
CVE-2026-72698Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-72697Grav CMS before 2.0.16 Path Traversal via media_directory | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-72696Grav CMS before 2.0.16 Symlink Following via createLockFile | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-56710Grav Login Plugin before 1.0.16 Privilege Escalation via Unlock | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityCritical |
CVE-2026-56709Grav before 3.9.2 Host Header Injection via sendInvitationEmail | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-56708Grav API Plugin before 1.0.16 SSRF via DNS Rebinding | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityMedium |
CVE-2026-56707Grav Flex Objects 1.4.0 through 1.4.7 Authorization Bypass via Shortcode | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/25/2026 | SeverityHigh |
CVE-2026-64852Grav API Plugin: Missing authorization on API-key generate/revoke lets any admin.login user forge keys for any account | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityHigh |
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityHigh |
CVE-2026-64851Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-shortcode-core | Published08/19/2026 | SeverityHigh |
CVE-2026-63408Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter | Exploitation statusNot known exploited | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityHigh |
CVE-2026-63407Grav API Plugin: CORS 'Access-Control-Allow-Origin: *' on Authenticated API Responses | Exploitation statusNot known exploited | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityHigh |
CVE-2026-62671CSRF in grav-plugin-login: anonymous attacker rotates a logged-in user's 2FA (TOTP) secret (no nonce on task=login.regenerate2FASecret) | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-login | Published08/19/2026 | SeverityMedium |
CVE-2026-62673Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityHigh |
CVE-2026-62672Grav: Authenticated ReDoS via regex_replace in Twig Sandbox | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityMedium |
CVE-2026-62667Grav API Plugin : API Key 'scopes' Never Enforced - Delegated Least-Privilege Keys Carry Full User ACL | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityHigh |
CVE-2026-62669Grav Login Plugin: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/19/2026 | SeverityHigh |
CVE-2026-62666Grav API Plugin: non-super api.users.write manager -> super-admin via createApiKey (incomplete fix of CVE-2026-59190); + 2FA strip of super | Exploitation statusNot known exploited | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityHigh |
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityCritical |
CVE-2026-62670Fail-open authorization in grav-plugin-flex-objects admin-next API: api.access user gets full CRUD on permission-less directories (requireFlexPermission missing else-deny) | Exploitation statusNot known exploited | FixYes | Affected productgrav-plugin-flex-objects | Published08/19/2026 | SeverityMedium |
CVE-2026-61842Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/19/2026 | SeverityMedium |
CVE-2026-61690Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityMedium |
CVE-2026-61607Grav API Plugin: Stored XSS via SVG Upload - API Media Pipeline Bypasses Sanitizer | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-api | Published08/19/2026 | SeverityMedium |
CVE-2026-53654Grav: Unauthenticated open redirect via login twofa_cancel _redirect | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/19/2026 | SeverityMedium |
CVE-2026-75837Grav before 2.0.14 Privilege Escalation via Group Access Field | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityCritical |
CVE-2026-75836Grav API Plugin before 1.0.14 Missing Authorization | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityHigh |
CVE-2026-75835Grav API Plugin before 1.0.14 Missing Authorization | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityCritical |
CVE-2026-75834Grav before 2.0.14 Stored XSS via Invalid UTF-8 Byte | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/18/2026 | SeverityMedium |
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypass | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityHigh |
CVE-2026-75832Grav API Plugin before 1.0.14 Authorization Bypass | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/18/2026 | SeverityCritical |
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URL | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityMedium |
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopy | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityHigh |
CVE-2026-75829grav-plugin-api before 1.0.15 Twig SSTI via translate endpoint | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/18/2026 | SeverityHigh |
CVE-2026-75828Grav before 2.0.15 Stored XSS via detectXss() Quote Bypass | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityCritical |
CVE-2026-75827Grav before 2.0.15 Arbitrary File Write via error_log | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityCritical |
CVE-2026-75107Grav Form Plugin before 9.1.19 Stored XSS via Field Properties | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/18/2026 | SeverityMedium |
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVG | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/18/2026 | SeverityMedium |
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.php | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/18/2026 | SeverityHigh |
CVE-2026-72833Grav 1.0.6 through 1.0.11 Privilege Escalation via Scoped API Keys | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypass | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityMedium |
CVE-2026-72831Grav through 2.0.11 Authentication Bypass via Flex Objects | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72829Grav before 1.0.13 API Key Scope Bypass via UsersController | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72828Grav before 1.0.13 API Key Scope Bypass via InvitationsController | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twig | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72826Grav before 1.0.13 Scope Bypass via createApiKey | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72825Grav before 1.0.13 API-key scope cap bypass via ReportsController | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72824Grav before 1.0.13 API Key Scope Bypass via PagesController | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72823Grav before 1.0.13 API-key scope cap bypass via DemoController | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/14/2026 | SeverityMedium |
CVE-2026-72822Grav before 1.0.13 Authentication Bypass via disable2fa | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityMedium |
CVE-2026-72820Grav 2.0.11 Path Traversal via Backup Profile Configuration | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityMedium |
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/14/2026 | SeverityHigh |
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermark | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/03/2026 | SeverityHigh |
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published08/03/2026 | SeverityHigh |
CVE-2026-69087Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig | Exploitation statusPublic exploit | FixYes | Affected productgrav-plugin-form | Published08/03/2026 | SeverityHigh |
CVE-2026-66400Grav Login Plugin before 3.8.13 Insufficient Session Expiration | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/29/2026 | SeverityMedium |
CVE-2026-65897Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/23/2026 | SeverityHigh |
CVE-2026-65896Grav API Plugin before 1.0.10 Path Traversal via move | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/23/2026 | SeverityHigh |
CVE-2026-65895Grav API Plugin before 1.0.10 Broken Access Control | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/23/2026 | SeverityHigh |
CVE-2026-65608Grav before 2.0.9 Remote Code Execution via FlexDirectory | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/23/2026 | SeverityHigh |
CVE-2026-65603Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/22/2026 | SeverityHigh |
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/21/2026 | SeverityCritical |
CVE-2026-65007Grav before 1.0.8 Missing Authorization on API Key Generation | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/21/2026 | SeverityHigh |
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/21/2026 | SeverityMedium |
CVE-2026-62387Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CVE-2026-62386Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CVE-2026-62237Grav < 2.0.4 ReDoS via regex_replace in Sandbox | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityMedium |
CVE-2026-62236grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityLow |
CVE-2026-62235Grav Flex-Objects < 1.4.3 Authorization Bypass via API | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published07/17/2026 | SeverityLow |
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocols | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CVE-2026-62233grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey | Exploitation statusNot known exploited | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CVE-2026-62232Grav < 2.0.4 2FA Bypass via Secret Regeneration | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityCritical |
CVE-2026-62231Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CVE-2026-62230Grav < 2.0.4 File Access Bypass via Case Variation | Exploitation statusPublic exploit | FixYes | Affected productgrav | Published07/17/2026 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan