PT-2026-99344 · Unknown · Grav Data Manager

·

CVE-2026-100673

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Grav Data Manager versions 1.0.1 through 1.4.4
Description Stored data entries in the item-detail view admin/templates/partials/item.html.twig are rendered without proper escaping due to the use of Twig's raw filter. In certain instances, a striptags('<br>') call is used, which can be bypassed by PHP's strip tags() function by preserving allowed tags and their attributes. This allows an unauthenticated visitor to submit a front-end form and store an HTML payload. When an administrator views the entry in the classic admin panel, the payload executes as JavaScript within the administrator's session and origin, utilizing their privileges and CSRF token. Execution happens automatically for list values, such as checkbox or multi-select fields, and upon hovering for ordinary text fields.
Recommendations Update Grav Data Manager to version 1.4.5.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100673
GHSA-863Q-9V8V-M9FV

Affected Products

Grav Data Manager