Junglewise Threat Intelligence

CVE-2026-11982: Grav CMS stored XSS in Admin2 Pages API

CVE-2026-11982 · Severity: info · CVSS 5.1 · Published 2026-06-18

Technologies: Grav API Plugin. Vendors: Grav.

Executive brief

Grav CMS, a popular flat-file content management system, contains a security vulnerability in its Admin2 Pages API. An attacker with low-level editing privileges can save malicious scripts into website pages. When other users or administrators view these pages, the scripts can execute in their browsers, potentially leading to unauthorized actions or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14. The root cause is located in the `validateChangedFields()` function within the Admin2/API partial page save path (specifically the PATCH /pages endpoint). While the system performed standard validation, it failed to execute `Validation::checkSafety()`, allowing `Security::detectXss()` to be bypassed. A non-superadmin editor can persist malicious event-handler payloads (e.g., img tags with onerror attributes) in page Markdown. These payloads execute when rendered on the frontend for any viewer, including administrators. A fix has been committed to the grav-plugin-api repository to enforce XSS safety checks during partial-field validation.

Affected products

  • Grav grav-plugin-api 1.7.52
  • Grav Grav CMS 2.0.0-rc.9
  • Grav Admin2 plugin 2.0.0-rc.14

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References

Related threats