Where
-Infinity
0

Grav GravGrav before 2.0.7 Remote Code Execution via Blueprint dynamicData

Risk 86
Severity
9.3
First published (updated )

Grav GravGrav Stored Cross-Site Scripting via Shortcode Attribute Handlers

Risk 34
Severity
5.1
First published (updated )

Grav GravGrav < 2.0.4 ReDoS via regex_replace in Sandbox

Risk 38
Severity
6
First published (updated )

Grav GravGrav < 2.0.4 2FA Bypass via Secret Regeneration

Risk 63
Severity
9.1
First published (updated )

Grav GravGrav < 2.0.4 File Access Bypass via Case Variation

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav GravGrav before 9.1.8 Arbitrary File Write via Twig-Processed Filename

Risk 60
Severity
7.2
First published (updated )

Grav GravGrav before 2.0.1 XSS via Twig String Concatenation

Risk 38
Severity
5.1
First published (updated )

Grav GravGrav before 2.0.2 Decompression Bomb via Forged ZIP Size

Risk 40
Severity
7.1
First published (updated )

Grav GravGrav: Unauthenticated denial of service via unbounded image derivative dimensions

Risk 47
Severity
8.7
First published (updated )

Grav GravGrav before 2.0.2 Config Exfiltration via offsetGet Filter

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grav GravGrav before 2.0.1 Decompression Bomb via ZipArchiver

Risk 40
Severity
7.1
First published (updated )

Grav GravGrav - Stored CSS Injection via Markdown Image resize() Action

Risk 29
Severity
4.8
First published (updated )

Grav GravGrav - Cross-Site Scripting in Admin Plugin Page Editor

Risk 34
Severity
5.1
First published (updated )

Grav GravGrav - XML External Entity Injection via SVG Upload

Risk 40
Severity
7.1
First published (updated )

Grav GravStored XSS via missing XSS safety check in Admin2 Pages API partial validation

Risk 32
Severity
5.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()

Risk 44
Severity
7.7
First published (updated )

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters

Risk 63
Severity
6.2
First published (updated )

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab

Risk 63
Severity
6.2
First published (updated )

Grav GravGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab

Risk 63
Severity
6.2
First published (updated )

Grav GravGrav Admin Plugin vulnerable to User Enumeration & Email Disclosure

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter

Risk 36
Severity
6.9
First published (updated )

getgrav gravGrav Exposes Password Hashes Leading to privilege escalation

Risk 66
Severity
7.2
First published (updated )

getgrav gravGrav is vulnerable to a DOS on the admin panel

Risk 30
Severity
4.9
First published (updated )

getgrav gravGrav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions

Risk 68
Severity
9.6
First published (updated )

getgrav gravGrav is vulnerable to Arbitrary File Read

Risk 55
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

getgrav gravGrav is vulnerable to Server-Side Template Injection (SSTI) via Forms

Risk 44
Severity
7.7
First published (updated )

getgrav gravGrav is vulnerable to RCE via SSTI through Twig Sandbox Bypass

Risk 79
Severity
8.8
First published (updated )

getgrav gravGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption

Risk 79
Severity
8.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203