Записи getgrav
74 опубликованных записей вендора getgrav.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 5,4 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 79,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-863 Incorrect Authorization3
- CWE-269 Improper Privilege Management3
- CWE-184 Incomplete List of Disallowed Inputs2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
74 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2021-21425Готовый эксплойт | Unauthenticated Arbitrary YAML Write/Update leads to Code Executiongetgrav · grav-plugin-admin · CWE-284 | Критическая9,8 | — | 80,6 % | 7 апр. 2021 г. |
53В плане | CVE-2024-27921Эксплойта нет | Grav File Upload Path Traversal vulnerabilitygetgrav · grav · CWE-22 | Высокая8,8 | — | 60,6 % | 21 мар. 2024 г. |
40В плане | CVE-2024-34082Эксплойта нет | Grav Arbitrary File Read to Account Takeovergetgrav · grav · CWE-269 | Критическая9,9 | — | 3,0 % | 15 мая 2024 г. |
39Наблюдать | CVE-2025-46199Эксплойта нет | Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the formgetgrav · grav · CWE-79 | Критическая9,8 | — | 0,8 % | 25 июл. 2025 г. |
38Наблюдать | CVE-2021-47812Эксплойта нет | GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)getgrav · grav · CWE-862 | Критическая9,3 | — | 2,2 % | 15 янв. 2026 г. |
37Наблюдать | CVE-2021-29440Proof of concept | Twig allowing dangerous PHP functions by defaultgetgrav · grav · CWE-94 | Высокая7,2 | — | 30,6 % | 13 апр. 2021 г. |
37Наблюдать | CVE-2024-28116Proof of concept | Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypassgetgrav · grav · CWE-94 | Высокая8,8 | — | 5,8 % | 21 мар. 2024 г. |
36Наблюдать | CVE-2025-50286Готовый эксплойт | A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/togetgrav · grav · CWE-434 | Высокая8,1 | — | 13,6 % | 6 авг. 2025 г. |
36Наблюдать | CVE-2023-37897Эксплойта нет | Server-side Template Injection (SSTI) in gravgetgrav · grav · CWE-74 | Высокая8,8 | — | 2,8 % | 18 июл. 2023 г. |
36Наблюдать | CVE-2025-66844Эксплойта нет | In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig angetgrav · grav · CWE-918 | Критическая9,1 | — | 0,3 % | 15 дек. 2025 г. |
35Наблюдать | CVE-2025-66294Готовый эксплойт | Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypassgetgrav · grav · CWE-94 | Высокая8,7 | — | 2,8 % | 1 дек. 2025 г. |
35Наблюдать | CVE-2024-28119Эксплойта нет | Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handlergetgrav · grav · CWE-94 | Высокая8,8 | — | 1,6 % | 21 мар. 2024 г. |
35Наблюдать | CVE-2024-28117Эксплойта нет | Grav vulnerable to Server Side Template Injection (SSTI)getgrav · grav · CWE-94 | Высокая8,8 | — | 1,4 % | 21 мар. 2024 г. |
35Наблюдать | CVE-2020-29553Эксплойта нет | The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious getgrav · grav cms · CWE-352 | Высокая8,8 | — | 1,4 % | 15 мар. 2021 г. |
35Наблюдать | CVE-2024-27923Эксплойта нет | Remote Code Execution by uploading a phar file using frontmattergetgrav · grav · CWE-287 | Высокая8,8 | — | 1,4 % | 20 мар. 2024 г. |
35Наблюдать | CVE-2024-28118Эксплойта нет | Grav vulnerable to Server Side Template Injection (SSTI)getgrav · grav · CWE-94 | Высокая8,8 | — | 1,2 % | 21 мар. 2024 г. |
35Наблюдать | CVE-2025-46198Эксплойта нет | Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attrgetgrav · grav · CWE-79 | Высокая8,8 | — | 0,6 % | 25 июл. 2025 г. |
35Наблюдать | CVE-2025-66299Эксплойта нет | Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMSgetgrav · grav · CWE-94 | Высокая8,8 | — | 0,6 % | 1 дек. 2025 г. |
35Наблюдать | CVE-2025-66295Эксплойта нет | Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruptiongetgrav · grav · CWE-22 | Высокая8,8 | — | 0,6 % | 1 дек. 2025 г. |
35Наблюдать | CVE-2026-42608Эксплойта нет | Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.getgrav · grav · CWE-22 | Высокая8,8 | — | 0,5 % | 11 мая 2026 г. |
35Наблюдать | CVE-2026-42843Эксплойта нет | grav-plugin-api: Grav API Privilege Escalation to Super Admingetgrav · grav-plugin-api · CWE-863 | Высокая8,8 | — | 0,5 % | 11 мая 2026 г. |
35Наблюдать | CVE-2026-42611Эксплойта нет | Grav: Stored XSS via Tag Injectiongetgrav · grav · CWE-79 | Высокая8,9 | — | 0,4 % | 11 мая 2026 г. |
35Наблюдать | CVE-2025-66296Эксплойта нет | Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeovergetgrav · grav · CWE-266 | Высокая8,8 | — | 0,3 % | 1 дек. 2025 г. |
34Наблюдать | CVE-2025-66301Готовый эксплойт | Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actionsgetgrav · grav · CWE-285 | Высокая8,6 | — | 1,3 % | 1 дек. 2025 г. |
34Наблюдать | CVE-2026-42844Эксплойта нет | Grav: Low-privileged API users can create super-admin accounts via blueprint-uploadgetgrav · grav · CWE-269 | Высокая8,7 | — | 0,5 % | 12 мая 2026 г. |
- CVE-2021-2142563На этой неделе
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %getgrav · grav-plugin-admin7 апр. 2021 г.
- CVE-2024-2792153В плане
Grav File Upload Path Traversal vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %getgrav · grav21 мар. 2024 г.
- CVE-2024-3408240В плане
Grav Arbitrary File Read to Account Takeover
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %getgrav · grav15 мая 2024 г.
- CVE-2025-4619939Наблюдать
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %getgrav · grav25 июл. 2025 г.
- CVE-2021-4781238Наблюдать
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %getgrav · grav15 янв. 2026 г.
- CVE-2021-2944037Наблюдать
Twig allowing dangerous PHP functions by default
ВысокаяCVSS 7,2Proof of conceptEPSS 31 %getgrav · grav13 апр. 2021 г.
- CVE-2024-2811637Наблюдать
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
ВысокаяCVSS 8,8Proof of conceptEPSS 6 %getgrav · grav21 мар. 2024 г.
- CVE-2025-5028636Наблюдать
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/to
ВысокаяCVSS 8,1Готовый эксплойтEPSS 14 %getgrav · grav6 авг. 2025 г.
- CVE-2023-3789736Наблюдать
Server-side Template Injection (SSTI) in grav
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %getgrav · grav18 июл. 2023 г.
- CVE-2025-6684436Наблюдать
In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig an
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %getgrav · grav15 дек. 2025 г.
- CVE-2025-6629435Наблюдать
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
ВысокаяCVSS 8,7Готовый эксплойтEPSS 3 %getgrav · grav1 дек. 2025 г.
- CVE-2024-2811935Наблюдать
Grav vulnerable to Server Side Template Injection (SSTI) via Twig escape handler
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %getgrav · grav21 мар. 2024 г.
- CVE-2024-2811735Наблюдать
Grav vulnerable to Server Side Template Injection (SSTI)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav21 мар. 2024 г.
- CVE-2020-2955335Наблюдать
The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav cms15 мар. 2021 г.
- CVE-2024-2792335Наблюдать
Remote Code Execution by uploading a phar file using frontmatter
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav20 мар. 2024 г.
- CVE-2024-2811835Наблюдать
Grav vulnerable to Server Side Template Injection (SSTI)
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav21 мар. 2024 г.
- CVE-2025-4619835Наблюдать
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code via the onerror attr
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav25 июл. 2025 г.
- CVE-2025-6629935Наблюдать
Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav1 дек. 2025 г.
- CVE-2025-6629535Наблюдать
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav1 дек. 2025 г.
- CVE-2026-4260835Наблюдать
Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %getgrav · grav11 мая 2026 г.
- CVE-2026-4284335Наблюдать
grav-plugin-api: Grav API Privilege Escalation to Super Admin
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %getgrav · grav-plugin-api11 мая 2026 г.
- CVE-2026-4261135Наблюдать
Grav: Stored XSS via Tag Injection
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %getgrav · grav11 мая 2026 г.
- CVE-2025-6629635Наблюдать
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %getgrav · grav1 дек. 2025 г.
- CVE-2025-6630134Наблюдать
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
ВысокаяCVSS 8,6Готовый эксплойтEPSS 1 %getgrav · grav1 дек. 2025 г.
- CVE-2026-4284434Наблюдать
Grav: Low-privileged API users can create super-admin accounts via blueprint-upload
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %getgrav · grav12 мая 2026 г.