Getgrav
13 known vulnerabilities
Top Products
Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security config
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca
Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.page
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configur
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/g
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configurat
Frequently Asked Questions
How many CVEs affect Getgrav?
Getgrav has 13 CVE records in our database, including 2 critical and 7 high severity vulnerabilities.
What are the most severe Getgrav vulnerabilities?
Getgrav has 2 critical severity (CVSS 9.0+) and 7 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Getgrav vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Getgrav products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Getgrav Vulnerabilities
CyberStrike scans your infrastructure for Getgrav vulnerabilities and provides real-time remediation guidance.
Get Started