Known Vulnerabilities for Grav Cms by Getgrav
Listed below are 5 of the newest known vulnerabilities associated with "Grav Cms" by "Getgrav".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65897 json | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authent... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65896 json | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POS... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65895 json | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowi... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65608 json | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() reso... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65603 json | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-65008 json | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Commo... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-65007 json | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin ... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-64628 json | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan o... | Not Provided | 2026-07-21 | 2026-07-23 |
| CVE-2026-62387 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS c... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62386 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query para... | Not Provided | 2026-07-17 | 2026-07-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Getgrav | Grav Cms | 1.7.7 | |||
| Application | Getgrav | Grav Cms | 1.7.6 | |||
| Application | Getgrav | Grav Cms | 1.7.5 | |||
| Application | Getgrav | Grav Cms | 1.7.4 | |||
| Application | Getgrav | Grav Cms | 1.7.3 | |||
| Application | Getgrav | Grav Cms | 1.7.1 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 | |||
| Application | Getgrav | Grav Cms | 1.7.0 |