PT-2026-85498 · Grav · Grav
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Grav versions 2.0.0 through 2.0.17
Description
Authenticated page editors can store Twig-assembled Cross-Site Scripting (XSS) payloads because save-time XSS detection is not applied to modular pages. Users with page-edit rights can create modular pages containing malicious Twig code that executes in the browsers of visitors, including those in administrator sessions, when the parent page is rendered.
Recommendations
Update Grav to a version later than 2.0.17.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grav