getgrav/grav Security Advisories for 2.0.0-beta.3 (27)
-
[HIGH] Grav CMS vulnerable to remote code execution via .zip file upload
PKSA-b2c2-gv41-gcc7 CVE-2026-72819 GHSA-r94f-hx44-8jqf
Affected version: <2.0.13
Reported by:
GitHub -
[HIGH] Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
PKSA-dzhx-7r7k-p6cx CVE-2026-75837 GHSA-xhfv-7758-r9hx
Affected version: <2.0.14
Reported by:
GitHub -
[MEDIUM] Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate
PKSA-ht1d-wm6t-8sdj CVE-2026-75834 GHSA-q2j8-x8hf-63ch
Affected version: <2.0.14
Reported by:
GitHub -
[CRITICAL] Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
PKSA-nc3c-xf26-g5gp CVE-2026-75827 GHSA-f8wv-xp27-6gq7
Affected version: <=2.0.14
Reported by:
GitHub -
[CRITICAL] Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
PKSA-tr1n-vmpf-rmt6 CVE-2026-75828 GHSA-vfmf-q6x9-cw96
Affected version: <=2.0.14
Reported by:
GitHub -
[HIGH] Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
PKSA-t3gq-ss3y-p7b7 CVE-2026-74907 GHSA-4v9q-p283-qc2m
Affected version: <=2.0.14
Reported by:
GitHub -
[HIGH] Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
PKSA-275t-x9d8-k5s3 CVE-2026-72695 GHSA-jq29-c7v8-rg55
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
PKSA-9871-4yy4-mgt8 CVE-2026-72697 GHSA-47ch-6w46-6xm7
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
PKSA-f7gk-wxm8-5j49 CVE-2026-76839 GHSA-3jhr-mxmx-38cx
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
PKSA-rk3g-1sfp-78gs CVE-2026-76846 GHSA-xjw5-q542-3vmr
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
PKSA-wz98-fgrh-3wq2 CVE-2026-72698 GHSA-p597-crqc-m349
Affected version: <2.0.16
Reported by:
GitHub -
[LOW] Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
PKSA-xzd7-91fp-yh97 CVE-2026-72701 GHSA-38p6-h87p-r4cg
Affected version: <=2.0.15
Reported by:
GitHub -
[LOW] Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
PKSA-ms14-tz6x-6sqm CVE-2026-72702 GHSA-9ccq-2jfg-qw33
Affected version: <=2.0.15
Reported by:
GitHub -
[MEDIUM] Grav: Stored XSS via Markdown audio/video media <source> URL
PKSA-12j4-4z12-p48k CVE-2026-75831 GHSA-6qw9-4vv5-jr97
Affected version: <=2.0.14
Reported by:
GitHub -
[MEDIUM] Grav: Stored XSS via quoted-attribute bypass in detectXss
PKSA-rstv-2c4g-sjjn CVE-2026-72832 GHSA-269c-h76q-8cxw
Affected version: >=1.5.2,<=2.0.12
Reported by:
GitHub -
[HIGH] Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
PKSA-7hs4-c5nt-m1jh CVE-2026-65608 GHSA-c4wf-2xxc-68qm
Affected version: >=1.7.0,<2.0.9
Reported by:
GitHub -
[HIGH] Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
PKSA-p6yn-thc9-dbs3 CVE-2026-62669 GHSA-7mgc-c7pq-3rr3
Affected version: <2.0.4
Reported by:
GitHub -
[MEDIUM] Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
PKSA-sq15-xbtt-m678 CVE-2026-61842 GHSA-mc5q-6hpj-rp7j
Affected version: <2.0.2
Reported by:
GitHub -
[MEDIUM] Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
PKSA-2vrn-cxz9-yg23 CVE-2026-61690 GHSA-928x-9mpw-8h56
Affected version: <2.0.1
Reported by:
GitHub -
[HIGH] Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
PKSA-1q9r-bgms-91mf CVE-2026-64850 GHSA-fj2p-qj2f-74v5
Affected version: <2.0.7
Reported by:
GitHub -
[MEDIUM] Grav: Authenticated ReDoS via regex_replace in Twig Sandbox
PKSA-wwkm-grbv-93ck CVE-2026-62672 GHSA-37f3-6p89-6qr9
Affected version: <2.0.4
Reported by:
GitHub -
[MEDIUM] Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
PKSA-rjzr-vkvg-cvmf GHSA-8hgv-xc77-jmcr
Affected version: <=2.0.19
Reported by:
GitHub -
[HIGH] Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
PKSA-wh99-p4gt-7bkp CVE-2026-62673 GHSA-vwg3-w8w3-pc79
Affected version: <2.0.4
Reported by:
GitHub -
[HIGH] Grav: Unauthenticated denial of service via unbounded image derivative dimensions
PKSA-pv12-m6cp-m9cd CVE-2026-53653 GHSA-4x9g-vw65-vvf9
Affected version: <1.7.53|>=2.0.0-beta.1,<2.0.0-rc.8
Reported by:
GitHub -
[MEDIUM] Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
PKSA-p98m-jfx1-qxw4 CVE-2026-55890 GHSA-pmf8-g7c8-7v54
Affected version: <=2.0.0-rc.8
Reported by:
GitHub -
[HIGH] Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()
PKSA-jw9z-qj9h-1drk CVE-2026-44738 GHSA-j274-39qw-32c9
Affected version: <=2.0.0-rc.1
Reported by:
GitHub -
[HIGH] Low-privileged Grav API users can create super-admin accounts via blueprint-upload
PKSA-jtpz-17pm-t9v9 CVE-2026-42844 GHSA-6xx2-m8wv-756h
Affected version: <2.0.0-beta.4
Reported by:
GitHub