Known Vulnerabilities for Grav by Getgrav
Listed below are 10 of the newest known vulnerabilities associated with "Grav" by "Getgrav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69089 json | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argu... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69088 json | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dyna... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-69087 json | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the red... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-66400 json | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where t... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-65897 json | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authent... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65895 json | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowi... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65608 json | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() reso... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65008 json | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Commo... | Not Provided | 2026-07-21 | 2026-07-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.7.0 | |||
| Application | Getgrav | Grav | 1.6.9 | |||
| Application | Getgrav | Grav | 1.6.8 |