Executive brief
Grav, a popular open-source content management system, contains a security flaw in its administration panel. An attacker with administrative privileges can inject malicious scripts into page titles, which then execute in the browsers of other administrators. This could lead to unauthorized actions being performed on behalf of users, sensitive data theft, or full account compromise.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS admin panel within the `/admin/pages/[page]` endpoint. The root cause is a failure to properly sanitize user input in the `data[header][title]` parameter when saving or editing a page. An attacker with high privileges (admin access) can inject a JavaScript payload into the page title. This script is subsequently executed when another user interacts with the 'move' function or views the affected page folder in the admin interface. The vulnerability is patched in version 1.7.49.5.
Affected products
- getgrav Grav < 1.7.49.5
Timeline
- 2026-05-05: patched: Fix committed to getgrav/grav-plugin-admin
- 2026-05-08: disclosed: GitHub Advisory published
- 2026-05-11: advisory: NVD published CVE-2026-44737