VYPR

Packagist (Composer) package

getgrav/grav

pkg:composer/getgrav/grav

Vulnerabilities (68)

  • CVE-2021-3818MedSep 27, 2021
    affected < 1.7.21fixed 1.7.21

    grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

  • CVE-2021-29440HigApr 13, 2021
    affected < 1.7.11fixed 1.7.11

    Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arbitrary code execution and elevate privile

  • CVE-2020-29553HigMar 15, 2021
    affected >= 1.7.0-beta.1, <= 1.7.0-rc.17

    The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF).

  • CVE-2020-29556MedMar 15, 2021
    affected >= 1.7.0-beta.1, <= 1.7.0-rc.17

    The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of CSR

  • CVE-2020-29555HigMar 15, 2021
    affected >= 1.7.0-beta.1, <= 1.7.0-rc.17

    The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. (This vulnerability can also be exploited by an unauthenticated attacker due to a lack of C

  • CVE-2020-11529MedApr 4, 2020
    affected < 1.6.23fixed 1.6.23

    Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.

  • CVE-2019-16126MedSep 9, 2019
    affected < 1.7.0-beta.8fixed 1.7.0-beta.8

    Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.

  • CVE-2018-5233MedMar 19, 2018
    affected < 1.3.0fixed 1.3.0

    Cross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/tools.

Page 4 of 4