VYPR

grav-plugin-shortcode-core

by Grav CMS

CVEs (2)

  • CVE-2026-64851HigAug 19, 2026
    risk 0.48cvss —epss 0.00

    Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode Core passes shortcode syntax through Security::detectXss() because it contains no literal less-than character,…

  • CVE-2026-85599HigSep 4, 2026
    risk 0.47cvss 7.2epss 0.00

    Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that…