VYPR
High severity7.6NVD Advisory· Published Mar 30, 2026· Updated Apr 6, 2026

CVE-2026-29924

CVE-2026-29924

Description

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Getgrav/Grav2 versions
    cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*range: <1.8.0
    • (no CPE)range: <= 1.7.x

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.