Vulnerabilidades em getgrav

102 resultados
Análise Vexday

O ecossistema de vulnerabilidades do Grav CMS acumula 59 CVEs catalogadas, com 5 classificadas como críticas e 4 contando com prova de conceito pública disponível — fatores que elevam o risco de exploração mesmo na ausência de registros confirmados no catálogo CISA KEV, cuja taxa permanece abaixo da média geral. A CVE mais preocupante no momento é CVE-2021-21425, com EPSS de 0,8047, indicando alta probabilidade estimada de exploração ativa, o que merece atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O volume de 14 novas CVEs nos últimos 90 dias aponta para uma cadência de descobertas elevada, sugerindo que a superfície de ataque do produto segue em expansão recente. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que tende a ser subestimado em triagens mas que, combinado com PoCs públicas, representa vetor relevante para comprometimento de sessões e escalada de impacto.

CVE-2021-21425CRITICALUnauthenticated Arbitrary YAML Write/Update leads to Code ExecutionEPSS 80.6%CVE-2024-27921HIGHGrav File Upload Path Traversal vulnerabilityEPSS 60.6%CVE-2021-29440HIGHTwig allowing dangerous PHP functions by defaultEPSS 30.6%CVE-2022-2073CRITICALCode Injection in getgrav/gravEPSS 10.4%CVE-2024-28116HIGHServer-Side Template Injection (SSTI) with Grav CMS security sandbox bypassEPSS 5.8%CVE-2023-34448HIGHGrav Server-side Template Injection (SSTI) via Twig Default FiltersEPSS 4.5%CVE-2021-3924HIGHPath Traversal in getgrav/gravEPSS 4.2%CVE-2026-42607CRITICALGrav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install FeatureEPSS 3.9%CVE-2024-34082HIGHGrav Arbitrary File Read to Account TakeoverEPSS 3.0%CVE-2025-66294HIGHGrav is vulnerable to RCE via SSTI through Twig Sandbox BypassEPSS 2.9%CVE-2023-37897HIGHServer-side Template Injection (SSTI) in gravEPSS 2.8%CVE-2021-29439HIGHPlugins can be installed with minimal admin privilegesEPSS 2.6%CVE-2021-3818MEDIUMReliance on Cookies without Validation and Integrity Checking in getgrav/gravEPSS 2.5%CVE-2023-34251CRITICALGrav Server Side Template Injection vulnerabilityEPSS 2.3%CVE-2023-34253HIGHGrav vulnerable to Server-side Template Injection (SSTI) via Denylist BypassEPSS 2.1%CVE-2023-34252HIGHGrav Server-side Template Injection via Insufficient Validation in filterFilterEPSS 2.1%CVE-2021-47812CRITICALGravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)EPSS 2.0%CVE-2022-0970HIGHCross-site Scripting (XSS) - Stored in getgrav/gravEPSS 1.8%CVE-2021-3799MEDIUMImproper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-adminEPSS 1.6%CVE-2024-28119HIGHGrav vulnerable to Server Side Template Injection (SSTI) via Twig escape handlerEPSS 1.6%