Grav · Admin2 · CVE-2026-11982
**Name of the Vulnerable Software and Affected Versions**
Grav version 2.0.0-rc.9 with Admin2 version 2.0.0-rc.14
**Description**
A stored cross-site scripting (XSS) issue exists in the Admin2 Pages API save flow due to a missing XSS safety check during partial validation. Stored XSS occurs when an application receives data from a user and includes that data within its later HTTP responses in an unsafe way, allowing an attacker to store malicious scripts on the server.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.