PT-2026-85498 · Grav · Grav

·

CVE-2026-85598

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grav versions 2.0.0 through 2.0.17
Description Authenticated page editors can store Twig-assembled Cross-Site Scripting (XSS) payloads because save-time XSS detection is not applied to modular pages. Users with page-edit rights can create modular pages containing malicious Twig code that executes in the browsers of visitors, including those in administrator sessions, when the parent page is rendered.
Recommendations Update Grav to a version later than 2.0.17.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85598
GHSA-FG8G-663R-F366

Affected Products

Grav