PT-2026-76931 · Grav · Grav
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Grav versions prior to 2.0.15
Description
Stored cross-site scripting occurs during the rendering of audio and video media via the
sourceParsedownElement() function. The issue arises because the media URL fragment is concatenated without being escaped into rawHtml source elements, which allows attackers to inject arbitrary HTML and JavaScript that executes within the sessions of users viewing the content.Recommendations
Update Grav to version 2.0.15 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav