CVE-2026-85599: Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters
Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is at risk from the injected code?
An attacker needs page-edit access to store a malicious [lorem] parameter or [details] summary parameter. The injected HTML or JavaScript executes for visitors to the affected rendered page, including administrators.
Which inputs should be reviewed for possible malicious content?
Review editable pages that use the [lorem] tag parameter or the [details] tag summary parameter. These values are rendered without escaping in affected versions.
What version addresses the vulnerability?
Grav Shortcode Core versions before 6.2.5 are affected. Upgrade to version 6.2.5 or later.