High severity7.6NVD Advisory· Published Mar 30, 2026· Updated Apr 6, 2026
CVE-2026-29924
CVE-2026-29924
Description
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
News mentions
0No linked articles in our index yet.