Grav vulnerability

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

Published 13 Sep 2026Updated 13 Sep 20261 sources
CVSS 1.8

Source timeline

CVE record published by NVDView source ↗