VYPR

grav-plugin-admin

by Grav CMS

Source repositories

CVEs (9)

  • CVE-2021-21425CriApr 7, 2021
    risk 0.70cvss 9.3epss 0.81

    Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method…

  • CVE-2021-29439HigApr 13, 2021
    risk 0.47cvss 7.2epss 0.03

    The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can obtain an arbitrary…

  • CVE-2020-36955MedJan 26, 2026
    risk 0.42cvss 6.4epss 0.01

    Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be…

  • CVE-2021-3920MedNov 19, 2021
    risk 0.35cvss 5.4epss 0.01

    grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3799MedSep 27, 2021
    risk 0.35cvss 5.4epss 0.02

    grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames

  • CVE-2026-85600MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result…

  • CVE-2026-61457HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.01

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with…

  • CVE-2026-61452MedJul 15, 2026
    risk 0.00cvss 5.3epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for…

  • CVE-2026-61454MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server…