PT-2026-76928 · Grav · Grav

·

CVE-2026-75828

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Grav versions prior to 2.0.15
Description A stored cross-site scripting issue exists in the detectXss() function. Authenticated editors can bypass event-handler detection by using unpaired quotes in unquoted attribute values. This allows the injection of event handlers, such as onerror=, which pass validation and execute within the browsers of visitors when page content is rendered.
Recommendations Update to version 2.0.15 or later. As a temporary workaround, restrict the permissions of authenticated editors to prevent them from modifying page content until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75828
GHSA-VFMF-Q6X9-CW96

Affected Products

Grav