Where
-Infinity
0

Vendor Risk Score

See how getgrav compares to other vendors in security performance

View Risk Score →

getgrav gravGrav before 2.0.9 Remote Code Execution via FlexDirectory

Risk 79
Severity
8.7
First published (updated )

getgrav Grav-plugin-apiGrav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator

Risk 62
Severity
8.6
First published (updated )

getgrav gravGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

Risk 36
Severity
6.9
First published (updated )

getgrav Grav-plugin-apiGrav - Arbitrary File Upload via Avatar Endpoint

Risk 26
Severity
5.3
First published (updated )

Grav GravGrav - Cross-Site Scripting in Admin Plugin Page Editor

Risk 34
Severity
5.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()

Risk 44
Severity
7.7
First published (updated )

composer/getgrav/gravGrav: Low-privileged API users can create super-admin accounts via blueprint-upload

Risk 79
Severity
8.7
First published (updated )

getgrav gravGrav: Stored XSS via Tag Injection

Risk 70
Severity
8.9
First published (updated )

getgrav gravGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

Risk 66
Severity
8.8
First published (updated )

getgrav gravGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav: Publisher-Level Stored XSS via Unquoted Event Attributes

Risk 55
Severity
8.5
First published (updated )

getgrav gravGrav: Sensitive Information Disclosure via Accounts Service Bypass

Risk 38
Severity
6.5
First published (updated )

getgrav gravGrav: Stored XSS via Markdown media attribute() action in Grav CMS

Risk 40
Severity
6.9
First published (updated )

getgrav Grav-plugin-apigrav-plugin-api: Grav API Privilege Escalation to Super Admin

Risk 79
Severity
8.8
First published (updated )

Grav Grav CMSXEE

Risk 58
Severity
7.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GravCMS GravCMSGravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)

Risk 86
Severity
9.8
First published (updated )

gravXSS

Risk 34
Severity
5.4
First published (updated )

gravSSRF

Risk 66
Severity
9.1
First published (updated )

Grav Grav CMSXSS

Risk 38
Severity
6.1
First published (updated )

Grav Admin pluginGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`

Risk 63
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters

Risk 63
Severity
6.2
First published (updated )

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab

Risk 63
Severity
6.2
First published (updated )

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab

Risk 63
Severity
6.2
First published (updated )

Grav Admin pluginGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`

Risk 33
Severity
6.8
First published (updated )

Grav GravGrav Admin Plugin vulnerable to User Enumeration & Email Disclosure

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav vulnerable to Information Disclosure via IDOR in Grav Admin Panel

Risk 38
Severity
6.5
First published (updated )

getgrav gravGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter

Risk 36
Severity
6.9
First published (updated )

getgrav gravGrav Exposes Password Hashes Leading to privilege escalation

Risk 66
Severity
7.2
First published (updated )

getgrav gravGrav is vulnerable to a DOS on the admin panel

Risk 30
Severity
4.9
First published (updated )

getgrav gravGrav vulnerable to Path Traversal allowing server files backup

Risk 37
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203