Exposición de Grav

CMS
129
score de exposición
737
sitios usan
0
en explotación
8
críticos
Análisis Vexday

O CMS Grav acumula 46 CVEs catalogadas, com 13 surgidas nos últimos 90 dias — volume recente que indica atenção contínua da comunidade de pesquisa à superfície de ataque da plataforma. Nenhuma vulnerabilidade consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, o que sugere ausência de exploração ativa confirmada até o momento, embora isso não elimine o risco. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão recorrente em aplicações de gerenciamento de conteúdo. A CVE mais preocupante no cenário atual é CVE-2024-27921, com EPSS de aproximadamente 0,61, indicando probabilidade relevante de exploração — equipes responsáveis por instâncias Grav devem priorizá-la nas verificações de atualização, especialmente considerando que há 3 CVEs de severidade crítica no portfólio total.

CVEs

89 resultados
CVE-2026-65008CRITICALGrav before 2.0.7 Remote Code Execution via Blueprint dynamicDataEPSS 0.8%CVE-2025-66297HIGHGrav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig InjectionEPSS 0.8%CVE-2023-34452MEDIUMGrav vulnerable to Self Cross Site Scripting in /forgot_passwordEPSS 0.6%CVE-2025-66299HIGHSecurity Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMSEPSS 0.6%CVE-2025-66295HIGHGrav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System CorruptionEPSS 0.5%CVE-2026-42608HIGHGrav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.EPSS 0.5%CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-61457MEDIUMGrav before 1.0.3 Remote Code Execution via File Upload Extension BypassEPSS 0.5%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.5%CVE-2025-66300HIGHGrav is vulnerable to Arbitrary File ReadEPSS 0.4%CVE-2026-42841MEDIUMGrav: Stored XSS via Markdown media attribute() action in Grav CMSEPSS 0.4%CVE-2025-66304MEDIUMGrav Exposes Password Hashes Leading to privilege escalationEPSS 0.4%CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2025-66305MEDIUMGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterEPSS 0.4%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.4%CVE-2025-66298HIGHGrav is vulnerable to Server-Side Template Injection (SSTI) via FormsEPSS 0.4%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.4%CVE-2026-42844HIGHGrav: Low-privileged API users can create super-admin accounts via blueprint-uploadEPSS 0.3%CVE-2025-66296HIGHGrav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account TakeoverEPSS 0.3%