Grav vulnerability

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 1.8

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.