Vulnerabilidades en getgrav

102 resultados
Análisis Vexday

O ecossistema de vulnerabilidades do Grav CMS acumula 59 CVEs catalogadas, com 5 classificadas como críticas e 4 contando com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros confirmados no catálogo CISA KEV, cuja taxa permanece abaixo da média geral. A CVE mais preocupante no momento é CVE-2021-21425, com EPSS de 0,8047, indicando alta probabilidade estimada de exploração ativa, o que merece atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O volume de 14 novas CVEs nos últimos 90 dias aponta para uma cadência de descobertas elevada, sugerindo que a superfície de ataque do produto segue em expansão recente. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado em triagens mas que, combinado com PoCs públicas, representa vetor relevante para comprometimento de sessões e escalada de impacto.

CVE-2025-66302MEDIUMGrav vulnerable to Path Traversal allowing server files backupEPSS 0.5%CVE-2026-61457MEDIUMGrav before 1.0.3 Remote Code Execution via File Upload Extension BypassEPSS 0.5%CVE-2026-42609HIGHGrav: Administrative Account Disruption and Privilege De-escalation via User Overwrite LogicEPSS 0.5%CVE-2025-66300HIGHGrav is vulnerable to Arbitrary File ReadEPSS 0.4%CVE-2026-42841MEDIUMGrav: Stored XSS via Markdown media attribute() action in Grav CMSEPSS 0.4%CVE-2025-66304MEDIUMGrav Exposes Password Hashes Leading to privilege escalationEPSS 0.4%CVE-2026-59193MEDIUMGrav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()EPSS 0.4%CVE-2025-66303MEDIUMGrav is vulnerable to a DOS on the admin panelEPSS 0.4%CVE-2025-66305MEDIUMGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' ParameterEPSS 0.4%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.4%CVE-2025-66298HIGHGrav is vulnerable to Server-Side Template Injection (SSTI) via FormsEPSS 0.4%CVE-2026-65897HIGHGrav API Plugin 1.0.9 Privilege Escalation via Invitations groupsEPSS 0.4%CVE-2026-42843HIGHgrav-plugin-api: Grav API Privilege Escalation to Super AdminEPSS 0.4%CVE-2026-42844HIGHGrav: Low-privileged API users can create super-admin accounts via blueprint-uploadEPSS 0.3%CVE-2025-66296HIGHGrav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account TakeoverEPSS 0.3%CVE-2025-66307MEDIUMGrav Admin Plugin vulnerable to User Enumeration & Email DisclosureEPSS 0.3%CVE-2026-65603HIGHGrav Login Plugin 3.8.11 Privilege Escalation via Profile UpdateEPSS 0.3%CVE-2026-58492CRITICALgrav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name InterpolationEPSS 0.3%CVE-2026-53653HIGHGrav: Unauthenticated denial of service via unbounded image derivative dimensionsEPSS 0.3%CVE-2026-42611HIGHGrav: Stored XSS via Tag InjectionEPSS 0.3%