Unrated severityNVD Advisory· Published Jun 18, 2026· Updated Jun 18, 2026
Stored XSS via missing XSS safety check in Admin2 Pages API partial validation
CVE-2026-11982
Description
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: =2.0.0-rc.14
Patches
Vulnerability mechanics
References
3- github.com/getgrav/grav-plugin-api/commit/b8ca62eddb7dbea92075a78b1c0a507f03d66d4amitrepatch
- fluidattacks.com/es/advisories/luismitrethird-party-advisory
- github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6mitrevendor-advisory
News mentions
0No linked articles in our index yet.