Known Vulnerabilities for Grav Admin by Getgrav
Listed below are 1 of the newest known vulnerabilities associated with "Grav Admin" by "Getgrav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65897 json | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authent... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65008 json | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Commo... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65007 json | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin ... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-64628 json | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan o... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-62386 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query para... | Not Provided | 2026-07-17 | 2026-07-23 |
| CVE-2026-62235 json | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows ... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62233 json | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, all... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-61454 json | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ i... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-61450 json | Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to ... | Not Provided | 2026-07-10 | 2026-07-10 |