Grav · Grav · CVE-2026-85598
**Name of the Vulnerable Software and Affected Versions**
Grav versions 2.0.0 through 2.0.17
**Description**
Authenticated page editors can store Twig-assembled Cross-Site Scripting (XSS) payloads because save-time XSS detection is not applied to modular pages. Users with page-edit rights can create modular pages containing malicious Twig code that executes in the browsers of visitors, including those in administrator sessions, when the parent page is rendered.
**Recommendations**
Update Grav to a version later than 2.0.17.