Medium severity6.1NVD Advisory· Published Jan 6, 2025· Updated Jun 17, 2026
CVE-2024-35498
CVE-2024-35498
Description
A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
getgrav/gravPackagist | <= 1.7.45 | — |
Affected products
3Patches
Vulnerability mechanics
References
3- r4vanan.medium.com/a-quick-dive-into-xss-vulnerability-in-grav-cms-v1-7-45-cve-2024-35498-fc236b7d74a0nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-m78c-qx99-mvw9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-35498ghsaADVISORY
News mentions
0No linked articles in our index yet.