Medium severity5.4NVD Advisory· Published Oct 27, 2021· Updated Jun 17, 2026
CVE-2021-3904
CVE-2021-3904
Description
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | < 1.7.24 | 1.7.24 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/getgrav/grav/commit/afc69a3229bb6fe120b2c1ea27bc6f196ed7284dnvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/b1182515-d911-4da9-b4f7-b4c341a62a8dnvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5jxc-hmqf-3f73ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3904ghsaADVISORY
News mentions
0No linked articles in our index yet.