pkg:Packagist/getgrav/grav
64 total CVEsCRITICAL4HIGH25MEDIUM21
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.4CVE-2026-42613Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups/accessfrom 0, < 2.0.0-beta.2
- CRITICAL9.1CVE-2026-42607Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Featurefrom 0, < 2.0.0-beta.2
- from 0, <= 1.7.49.5
- from 0, < 1.7.42
- from 0, < 2.0.0-beta.2
- HIGH8.8CVE-2025-66295Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruptionfrom 0, < 1.8.0-beta.27
- HIGH8.8CVE-2025-66299Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)from 0, < 1.8.0-beta.27
- HIGH8.8CVE-2025-66296Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeoverfrom 0, < 1.8.0-beta.27
- from 0, < 1.7.45
- from 0, < 1.7.45
- from 0, < 1.7.45
- from 0, < 1.7.45
- from 0, < 1.7.45
- from 0, < 1.7.43
- >= 1.7.0-beta.1, <= 1.7.0-rc.17
- from 0, <= 1.7.24
- from 0, < 2.0.0-beta.2
- from 0, < 1.8.0-beta.27
- from 0, < 1.7.46
- from 0, < 1.7.11
- HIGH8.1CVE-2026-42609Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logicfrom 0, < 2.0.0-beta.2
- >= 1.7.0-beta.1, <= 1.7.0-rc.17
- HIGH7.7CVE-2026-44738Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()from 0, < 2.0.0-rc.2
- from 0, < 1.7.42.2
- from 0, < 1.7.42
- from 0, < 1.7.42
- from 0, < 1.7.42
- from 0, < 1.7.34
- from 0, < 1.7.31
- from 0, < 1.8.0-beta.27
- MEDIUM6.5CVE-2026-42610Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypassfrom 0, < 2.0.0-beta.2
- from 0, < 1.8.0-beta.27
- from 0, < 1.7.24
- from 0, < 1.7.21
- from 0, < 1.8.0-beta.27
- from 0, <= 1.7.49
- from 0, < 1.3.0
- from 0, < 1.6.23
- from 0, < 1.7.0-beta.8
- from 0, < 1.7.28
- >= 1.7.0-beta.1, <= 1.7.0-rc.17
- from 0, < 2.0.0-beta.2
- from 0, <= 1.7.49.5
- from 0
- from 0, < 1.7.33
- from 0, < 2.0.0-beta.2
- from 0, < 1.8.0-beta.27
- from 0, < 2.0.0-beta.2
- from 0, < 1.7.31
- from 0, < 1.8.0-beta.27
- from 0, < 1.7.49.5
- from 0, < 2.0.0-beta.4
- —CVE-2026-42608Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash componentfrom 0, < 2.0.0-beta.2
- from 0, < 1.8.0-beta.27
- from 0, < 1.8.0-beta.27
- —CVE-2025-66310Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tabfrom 0, < 1.8.0-beta.27
- —CVE-2025-66309Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tabfrom 0, < 1.8.0-beta.27
- —CVE-2025-66297Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injectionfrom 0, < 1.8.0-beta.27
- —CVE-2025-66308Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`from 0, < 1.8.0-beta.27
- —CVE-2025-66305Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameterfrom 0, < 1.8.0-beta.27
- —CVE-2025-66312Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`from 0, < 1.8.0-beta.27
- —CVE-2025-66311Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parametersfrom 0, < 1.11.0-beta.1
- —CVE-2025-66301Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actionsfrom 0, < 1.8.0-beta.27
- from 0, <= 1.7.45