By vendor

Getgrav vulnerabilities

Known CVEs affecting Getgrav products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2020-37256MEDIUM 5.4

    Grav, a popular flat-file CMS, contains a cross-site scripting (XSS) flaw in its Admin plugin page editor affecting versions before 1.6.30. An authenticated user with page editing rights can embed malicious scripts into page content. When another user (typically an administrator) views or interacts with that page, the injected script executes in their browser context, potentially allowing the attacker to escalate privileges, modify site content, or install unauthorized plugins that grant deeper system access.