Junglewise Threat Intelligence

CVE-2026-64628: Grav stored XSS in shortcode-core attribute handlers

CVE-2026-64628 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Getgrav Grav, Grav. Vendors: Getgrav, Grav.

Executive brief

Grav, a popular open-source content management system, is vulnerable to a security flaw that allows users with page-editing permissions to embed malicious scripts into website content. These scripts can automatically execute in the browsers of other visitors, including site administrators. This could allow an attacker to hijack administrative sessions, steal sensitive data, or perform unauthorized actions on the website.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Grav's shortcode-core attribute handlers due to insufficient input validation. The 'Security::detectXss()' function only filters for literal angle brackets (<), which are not required for shortcode syntax. An attacker with 'admin.pages' permissions can craft a shortcode with a malicious attribute (e.g., using a double quote to break out of an HTML attribute) that injects event handlers like 'onmouseover'. When the page is rendered, the injected script executes in the context of any viewer's session. This can be used to steal admin nonces and hijack high-privilege sessions. The vulnerability affects versions up to and including 6.2.1.

Affected products

  • getgrav Grav <= 6.2.1

Timeline

  • 2026-07-07: advisory: GitHub Security Advisory published
  • 2026-07-21: disclosed: NVD publication date

References

Related threats