vendor

getgrav

15 thingsrelated by NVD

Its products

grav 12 grav-plugin-admin 3

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages…
CVE-2025-66312
Severity medium
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages…
CVE-2025-66311
Severity medium
This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages…
CVE-2025-66307
Severity medium
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav…
CVE-2025-66306
Severity medium
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel…
CVE-2025-66304
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to…
CVE-2025-66303
Severity medium
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing…
CVE-2025-66302
Severity medium
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST…
CVE-2025-66301
Severity critical
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server…
CVE-2025-66300
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows…
CVE-2025-66299
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details…
CVE-2025-66298
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav…
CVE-2025-66297
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the…
CVE-2025-66296
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin…
CVE-2025-66295
Severity high
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows…
CVE-2025-66294
Severity high