Unknown · Grav Data Manager · CVE-2026-100673
**Name of the Vulnerable Software and Affected Versions**
Grav Data Manager versions 1.0.1 through 1.4.4
**Description**
Stored data entries in the item-detail view `admin/templates/partials/item.html.twig` are rendered without proper escaping due to the use of Twig's `raw` filter. In certain instances, a `striptags('<br>')` call is used, which can be bypassed by PHP's `strip tags()` function by preserving allowed tags and their attributes. This allows an unauthenticated visitor to submit a front-end form and store an HTML payload. When an administrator views the entry in the classic admin panel, the payload executes as JavaScript within the administrator's session and origin, utilizing their privileges and CSRF token. Execution happens automatically for list values, such as checkbox or multi-select fields, and upon hovering for ordinary text fields.
**Recommendations**
Update Grav Data Manager to version 1.4.5.