Loading HuntDB...

getgrav

4 Products 26 CVEs

CVE Severity Distribution (All Time)

Critical
3
High
16
Medium
7
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-34082 HIGH 1 year, 3 months ago

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twi…

CVE-2024-28119 HIGH 1 year, 5 months ago

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from gra…

CVE-2024-28118 HIGH 1 year, 5 months ago

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Gra…

CVE-2024-28117 HIGH 1 year, 5 months ago

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDanger…

CVE-2024-28116 HIGH 1 year, 5 months ago

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI…

CVE-2024-27921 HIGH 1 year, 5 months ago

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior …

CVE-2024-27923 HIGH 1 year, 6 months ago

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …

CVE-2023-37897 HIGH 2 years, 1 month ago

Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vu…

CVE-2023-34452 MEDIUM 2 years, 2 months ago

Grav is a flat-file content management system. In versions 1.7.42 and prior, the "/forgot_password" page has a self-reflected cross-site scripting vu…

CVE-2023-34448 HIGH 2 years, 2 months ago

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability i…