VYPR
High severity7.6NVD Advisory· Published Mar 30, 2026· Updated Apr 6, 2026

CVE-2026-29924

CVE-2026-29924

Description

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

Affected products

1
  • cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
    Range: <1.8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.