Known Vulnerabilities for Getgrav/grav by Trilby Media
Listed below are 10 of the newest known vulnerabilities associated with "Getgrav/grav" by "Trilby Media".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69087 json | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the red... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-62387 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS c... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62386 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query para... | Not Provided | 2026-07-17 | 2026-07-23 |
| CVE-2026-62231 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a r... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-61457 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controlle... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61456 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/medi... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-61454 json | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ i... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-61452 json | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT ... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-58655 json | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template i... | Not Provided | 2026-07-15 | 2026-07-15 |