Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44738 |
|
Information Disclosure in getgrav/grav (CVE-2026-44738)
vulnerability in getgrav/grav (CVE-2026-44738). Confidential information can be exposed externally. Exploitable via ``admin.pages``. Mitigation: upgrade to `2.0.0-rc.2` or later.
|
| CVE-2026-42611 |
|
Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-42611)
cross-site scripting in getgrav/grav (CVE-2026-42611). Confidential information can be exposed externally. Exploitable via `POST /grav-log`. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42612 |
|
Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-42612)
cross-site scripting in getgrav/grav (CVE-2026-42612). Confidential information can be exposed externally. Exploitable via ``onerror``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42841 |
|
Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-42841)
cross-site scripting in getgrav/grav (CVE-2026-42841). Risk of unauthorized operations or information disclosure. Exploitable via ``onload``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42608 |
|
Path Traversal in getgrav/grav (CVE-2026-42608)
path traversal in getgrav/grav (CVE-2026-42608). Confidential information can be exposed externally. Exploitable via `POST /contact`. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42609 |
|
Privilege Escalation in getgrav/grav (CVE-2026-42609)
vulnerability in getgrav/grav (CVE-2026-42609). Data can be tampered with by attackers. Exploitable via ``d904efc33``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42610 |
|
Authorization Flaw in getgrav/grav (CVE-2026-42610)
vulnerability in getgrav/grav (CVE-2026-42610). Confidential information can be exposed externally. Exploitable via ``editor_chen``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|