PatchSiren

getgrav CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH getgrav CVE published 2026-08-14

CVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. A holder of a narrow-scope API key on a su [truncated]

MEDIUM getgrav CVE published 2026-08-14

CVE-2026-72821

The CVE-2026-72821 record indicates a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter in Grav Form plugin versions before 9.1.15. Attackers with form authoring permissions can inject HTML and script payloads that execute in the browsers of visitors and administrators viewing the form. This vulnerability has a CVSS score of 5.1 and a seve [truncated]

MEDIUM getgrav CVE published 2026-08-14

CVE-2026-72820

CVE-2026-72820 debrief based on CVE Program and NVD records. The vulnerability affects Grav versions before 2.0.13, allowing attackers with profile editor access to archive directories outside GRAV_ROOT. This could expose sensitive files from locations like /opt, /mnt, or /srv. Defenders should assess exposure and prioritize remediation based on the CVE record and NVD entry details. The vulnerability has [truncated]

HIGH getgrav CVE published 2026-08-14

CVE-2026-72819

CVE-2026-72819 is a remote code execution vulnerability in Grav CMS before version 2.0.13, specifically in the Flex Objects plugin settings validation. Authenticated users can execute arbitrary code by uploading a ZIP file containing PHP code, bypassing routine name validation using array notation. This vulnerability allows attackers to write PHP files to the web root for execution. Defenders should asses [truncated]

HIGH getgrav CVE published 2026-08-03

CVE-2026-69089

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T14:16:29.420Z and has not been modified since then. The NVD entry is currently Deferred. This path traversal vulnerability in Grav CMS 2.0.10's ImageMedium::watermark() function allows attackers to disclose arbitrary image files outside the Grav media sandbox by crafting Markdown image syntax wit [truncated]

HIGH getgrav CVE published 2026-08-03

CVE-2026-69088

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T14:16:29.253Z and has not been modified since then. The NVD entry is currently Deferred. Grav CMS versions 2.0.7 through 2.0.10 are vulnerable to an issue allowing an attacker with page-editing rights to plant a directive in a page's form-field frontmatter that invokes an arbitrary public static [truncated]

HIGH getgrav CVE published 2026-08-03

CVE-2026-69087

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. This vulnerability allows an unauthenticated form submitter to cause a 302 redirect to an arbitrary external site, enabling phishing. Organizations using the Grav form plugin, especially those with publicly accessible forms, should be aware of this vulnerability and take steps to mitigate it. The CVE rec [truncated]

HIGH getgrav CVE published 2026-07-23

CVE-2026-65897

The Grav API Plugin, specifically versions before 1.0.10, contains a vulnerability that allows authenticated api.users.write callers to assign invited accounts to groups granting api.super permissions due to inadequate validation of the groups field in InvitationsController::create(). This oversight enables attackers to create invitation records with elevated group membership, potentially leading to full [truncated]

HIGH getgrav CVE published 2026-07-23

CVE-2026-65896

The Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 is vulnerable to path traversal attacks due to improper validation of the slug field in the POST /pages/{route}/move endpoint. An authenticated API caller with the api.pages.write permission can supply path traversal sequences to move an entire page directory to an arbitrary writable location outside user/pages/, including outsid [truncated]

HIGH getgrav CVE published 2026-07-23

CVE-2026-65895

The CVE-2026-65895 vulnerability affects Grav API Plugin versions before 1.0.10, allowing authenticated users with 'api.config.write' privileges to modify security-critical plugin configuration scopes. This could lead to credential brute-forcing attacks and CORS policy changes. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. Administrators and users should be aware of this vulnerabili [truncated]

HIGH getgrav CVE published 2026-07-22

CVE-2026-65603

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contains a high-severity privilege escalation vulnerability. The flaw exists in the authenticated profile self-update handler, which fails to strip privilege fields from user-submitted form data. This allows low-privilege authenticated users to escalate privileges to super-admin, potentially enabling admin panel access, scheduler abuse, and Twig [truncated]

CRITICAL getgrav CVE published 2026-07-21

CVE-2026-65008

CVE-2026-65008 is a remote code execution vulnerability in Grav 2.0.4, which was fixed in version 2.0.7. The vulnerability exists in the Blueprint::dynamicData() method, where a Class::method callable string and its arguments are passed directly to call_user_func_array() without any allowlist. This allows an authenticated account with the admin.pages (or api.pages.write) permission to plant a malicious ca [truncated]

HIGH getgrav CVE published 2026-07-17

CVE-2026-62387

The Grav API plugin before version 1.0.0-rc.16 had a misconfigured CORS setting, allowing unauthorized cross-origin requests. This vulnerability, CVE-2026-62387, was made public on 2026-07-17. The plugin's default configuration included an Access-Control-Allow-Origin header set to *, which could be exploited by attackers to read sensitive data and perform actions as the token's user. The vulnerability is [truncated]

HIGH getgrav CVE published 2026-07-17

CVE-2026-62386

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 has a security vulnerability. It accepts JWT access tokens through the ?token= URL query parameter on every API route due to a fallback in JwtAuthenticator::extractBearerToken. This causes tokens to be logged in web server access logs, leaked via the Referer header, stored in browser history, and captured by upstream proxy and CDN logs. A le [truncated]

LOW getgrav CVE published 2026-07-17

CVE-2026-62236

A cross-site request forgery (CSRF) vulnerability exists in grav-plugin-login before version 3.8.11. The vulnerability is located in the login.regenerate2FASecret frontend task, which allows an attacker to regenerate and persist a new TOTP secret for the authenticated session user without proper anti-CSRF measures. This can be exploited by luring a logged-in victim to an off-site page, causing the victim' [truncated]

LOW getgrav CVE published 2026-07-17

CVE-2026-62235

CVE-2026-62235 is a low-severity vulnerability in Grav Flex-Objects before version 1.4.3. The vulnerability is caused by a broken access control in the admin-next REST API, allowing authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. This can lead to unauthorized access and modification of objects in directories without explicit permi [truncated]

HIGH getgrav CVE published 2026-07-17

CVE-2026-62233

CVE-2026-62233 is a high-severity vulnerability in grav-plugin-api before version 1.0.6. The vulnerability allows non-super admin users with api.users.write manager privileges to escalate to super-admin status by exploiting the createApiKey, generate2fa, and disable2fa endpoints. This could lead to full instance takeover by minting API keys bound to super-admin accounts or stripping 2FA from super-admin users.

CRITICAL getgrav CVE published 2026-07-17

CVE-2026-62232

CVE-2026-62232 is a critical vulnerability in Grav before 2.0.4 that allows attackers to bypass two-factor authentication (2FA) by regenerating the 2FA secret. This vulnerability has a CVSS score of 9.1 and is considered critical. The vulnerability exists in the login plugin of Grav, where the regenerate2FASecret task only checks for user existence, not authorization, during the pending TOTP challenge win [truncated]

HIGH getgrav CVE published 2026-07-17

CVE-2026-62231

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass vulnerability. API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, allowing a key created with limited scopes (e.g., read-only) to perform any write, delete, or administrative oper [truncated]

HIGH getgrav CVE published 2026-07-17

CVE-2026-62230

CVE-2026-62230 is a high-severity vulnerability in Grav, a popular content management system. The vulnerability arises from the default .htaccess file and reference webserver-configs/htaccess.txt file that ships with Grav versions before 2.0.4. These files contain rules that block access to sensitive file types such as .yaml, .php, and .json. However, these rules lack the [NC] flag, which makes the extens [truncated]

HIGH getgrav CVE published 2026-07-11

CVE-2026-61454

The Grav Admin2 plugin before 2.0.4 discloses sensitive information via a global JavaScript variable. This CVE record was published on 2026-07-11T14:16:23.630Z and has not been modified since then. The vulnerability allows an unauthenticated attacker to fingerprint the deployment and select version-specific exploits without reconnaissance. Users of Grav Admin2 plugin versions before 2.0.4 should update to [truncated]

MEDIUM Getgrav CVE published 2026-07-10

CVE-2026-59193

CVE-2026-59193 is a vulnerability in Grav, a file-based Web platform, where an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool. This issue arises because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. The vulnerability is fixed in version 2.0.0. Af [truncated]

CRITICAL getgrav CVE published 2026-07-10

CVE-2026-58492

CVE-2026-58492 is a critical SQL injection vulnerability in the grav-plugin-database plugin for Grav CMS. The vulnerability allows attacker-controlled table names to execute arbitrary SQL against the configured database. This issue is fixed in version 1.2.0. Affected deployments should be reviewed for exposure and patched urgently. The grav-plugin-database plugin for Grav CMS has a critical SQL injection [truncated]

MEDIUM getgrav CVE published 2026-07-10

CVE-2026-55890

CVE-2026-55890 is a stored XSS vulnerability in Grav, a file-based web platform, due to an incomplete fix for CVE-2026-42841. The issue allows an editor to save malicious Markdown image style parameters that are written into the rendered img style attribute without proper sanitization. This vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. Users of Grav versions prior to 2.0.0-rc [truncated]

HIGH getgrav CVE published 2026-07-10

CVE-2026-53653

CVE-2026-53653 is a high-severity vulnerability in Grav, a file-based web platform. An unauthenticated visitor can exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions. This issue is fixed in Grav versions 1.7.53 and 2.0.0-rc.8. The vulnerability class is related to image derivative generation, and the likely operational impact is server r [truncated]

MEDIUM getgrav CVE published 2026-07-10

CVE-2026-61456

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Security::sanitizeSVG(), so an authenticated attacker with the api.media.write permission can upload an SVG containing arbitrary JavaScript. The file is stored unmod [truncated]

HIGH getgrav CVE published 2026-07-10

CVE-2026-61455

CVE-2026-61455 is a high-severity vulnerability in Grav, a popular content management system, caused by a decompression bomb in ZipArchiver::extract(). The vulnerability allows attackers to supply a crafted ZIP archive that expands to fill available disk space, causing denial of service by exhausting storage resources. This issue affects Grav versions prior to 2.0.1.

HIGH getgrav CVE published 2026-07-10

CVE-2026-61450

CVE-2026-61450 is a high-severity vulnerability in Grav, a popular open-source content management system. The vulnerability allows a page author to bypass the Twig sandbox and exfiltrate configuration secrets, including sensitive information such as SMTP credentials, API keys, and plugin DB credentials. This issue arises from an incomplete fix for a previous vulnerability (GHSA-j274-39qw-32c9). Although t [truncated]

HIGH getgrav CVE published 2026-07-08

CVE-2026-58656

The Grav API plugin before version 1.0.0-rc.16 has a security vulnerability that allows unauthenticated attackers to make fully authenticated cross-origin API requests. This is possible because the plugin accepts JWT tokens via the ?token= URL query parameter and responds with an Access-Control-Allow-Origin: * header. Attackers who obtain a leaked JWT token can create persistent backdoor super-admin accou [truncated]