-Infinity
0

Grav Grav CMSGrav CMS before 2.0.11 Path Traversal via watermark

Risk 47
Severity
8.7
First published (updated )

Grav Grav CMSGrav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint

Risk 62
Severity
8.6
First published (updated )

Grav GravGrav before 2.0.7 Remote Code Execution via Blueprint dynamicData

Risk 86
Severity
9.3
First published (updated )

Grav GravGrav Stored Cross-Site Scripting via Shortcode Attribute Handlers

Risk 34
Severity
5.1
First published (updated )

Grav Grav CMS scheduler-webhook pluginAuthentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check

Risk 43
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav Grav API plugin (getgrav/grav-plugin-api)Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin

Risk 48
Severity
7.1
First published (updated )

Grav GravGrav < 2.0.4 ReDoS via regex_replace in Sandbox

Risk 38
Severity
6
First published (updated )

Grav Grav Flex-ObjectsGrav Flex-Objects < 1.4.3 Authorization Bypass via API

Risk 46
Severity
2.3
First published (updated )

Grav GravGrav < 2.0.4 2FA Bypass via Secret Regeneration

Risk 63
Severity
9.1
First published (updated )

Grav GravGrav < 2.0.4 File Access Bypass via Case Variation

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav GravGrav before 9.1.8 Arbitrary File Write via Twig-Processed Filename

Risk 60
Severity
7.2
First published (updated )

Grav GravGrav before 2.0.1 XSS via Twig String Concatenation

Risk 38
Severity
5.1
First published (updated )

Grav GravGrav before 2.0.2 Decompression Bomb via Forged ZIP Size

Risk 40
Severity
7.1
First published (updated )

getgrav gravGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()

Risk 36
Severity
6.9
First published (updated )

Grav grav-plugin-adminGrav Admin Plugin — IDOR Privilege Escalation via saveUser()

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav GravGrav: Unauthenticated denial of service via unbounded image derivative dimensions

Risk 47
Severity
8.7
First published (updated )

Grav Grav API plugin (getgrav/grav-plugin-api)Grav before 1.0.3 Stored XSS via SVG Upload API

Risk 32
Severity
5.1
First published (updated )

Grav GravGrav before 2.0.2 Config Exfiltration via offsetGet Filter

Risk 40
Severity
7.1
First published (updated )

Grav GravGrav before 2.0.1 Decompression Bomb via ZipArchiver

Risk 40
Severity
7.1
First published (updated )

Grav GravGrav - Stored CSS Injection via Markdown Image resize() Action

Risk 29
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav Grav CMSGrav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection

Risk 86
Severity
9.3
First published (updated )

Grav GravGrav - Cross-Site Scripting in Admin Plugin Page Editor

Risk 34
Severity
5.1
First published (updated )

Grav GravGrav - XML External Entity Injection via SVG Upload

Risk 40
Severity
7.1
First published (updated )

Grav GravStored XSS via missing XSS safety check in Admin2 Pages API partial validation

Risk 32
Severity
5.1
First published (updated )

getgrav gravGrav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()

Risk 44
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav Grav CMSGrav CMS Cache Value FileCache.php doGet deserialization

Risk 28
Severity
1.3
EPSS
0.06%
First published (updated )

Grav Grav CMSXEE

Risk 58
Severity
7.6
First published (updated )

Grav Grav CMSGrav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

Grav Grav CMSXSS

Risk 38
Severity
6.1
First published (updated )

Grav Admin pluginGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`

Risk 63
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203