Technology · Packagist
getgrav/grav (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 63 vulnerabilities in getgrav/grav (Packagist): 0 in the last 7 days and 49 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-72819, was published on 17 September 2026.
- Last 7 days
- 0
- Last 90 days
- 49
- Critical, all time
- 4
- Exploited in the wild
- 0
About getgrav/grav (Packagist)
A flat-file content management system.
Latest getgrav/grav (Packagist) vulnerabilities
- CVE-2026-72819: Grav CMS remote code execution via .zip file uploadhighCVSS 8.8EPSS 0.9%
- CVE-2026-75827: Grav Blueprint bare-function arbitrary file write via error_loghighCVSS 8.8EPSS 0.9%
- CVE-2026-74907: Grav path traversal in static asset servermediumCVSS 5.9EPSS 0.4%
- CVE-2026-75831: Grav stored XSS via Markdown audio/video source URLhighCVSS 7.6EPSS 0.4%
- CVE-2026-72832: Grav stored XSS via quoted-attribute bypass in detectXssmediumCVSS 5.4EPSS 0.3%
- CVE-2026-69089: Grav CMS path traversal in ImageMedium watermarkhighCVSS 6.5EPSS 0.5%
- CVE-2026-69088: Grav CMS incomplete callable validation in blueprint dynamic fieldshighCVSS 8.1EPSS 0.4%
- CVE-2026-61842: Grav Twig sandbox config exfiltration via offsetGet and dump filtersmediumCVSS 6.5EPSS 0.4%
- CVE-2026-61690: Grav ZipArchiver decompression bomb via missing extraction limitsmediumCVSS 6.5EPSS 0.5%
- Grav UserInterface offsetGet/offsetExists Twig sandbox bypassmediumCVSS 6.5
- Grav incomplete Twig sandbox denylist information disclosurehighCVSS 7.5
- Grav CMS Twig sandbox bypass in configuration variablesmediumCVSS 6.5
- Grav CMS timing attack on nonce verification in CSRF protectionlowCVSS 3.7
- Grav CMS origin validation bypass in referrer headermediumCVSS 5.4
- Grav path traversal in MediaUploadTrait::deleteFilehighCVSS 8.1
- Grav CMS path traversal in media_directory() Twig functionmediumCVSS 6.5
- CVE-2026-76846: Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to…highCVSS 7.5EPSS 0.4%
- CVE-2026-76839: Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and…highCVSS 7.7EPSS 0.5%
- CVE-2026-72702: Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods…mediumCVSS 5.4EPSS 0.1%
- CVE-2026-72701: Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string…lowCVSS 3.7EPSS 0.3%
- CVE-2026-72698: Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-72697: Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-72695: Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated…highCVSS 8.1EPSS 0.9%
- Grav CMS cross-site scripting via Twig sandbox asset injectionmediumCVSS 5.1
- CVE-2026-64850: Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in…highCVSS 8.7EPSS 0.5%
Most severe getgrav/grav (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42613: Grav Login plugin privilege escalation in registration handlercriticalCVSS 9.4
- CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-42608: Grav Path Traversal and Arbitrary File Write in FormFlashcriticalCVSS 9.1
- CVE-2026-42607: Grav Remote Code Execution via Direct Install ZIP uploadcriticalCVSS 9.1
- CVE-2026-42611: Grav stored XSS via SVG tag injection in Admin PluginhighCVSS 8.9
- CVE-2026-65608: Grav remote code execution in FlexDirectory dynamic data fieldshighCVSS 8.8EPSS 1.3%
- CVE-2026-72819: Grav CMS remote code execution via .zip file uploadhighCVSS 8.8EPSS 0.9%
- CVE-2026-75827: Grav Blueprint bare-function arbitrary file write via error_loghighCVSS 8.8EPSS 0.9%
- CVE-2026-42844: Grav privilege escalation via arbitrary file upload in blueprint-upload APIhighCVSS 8.8EPSS 0.0%
- Grav Blueprint dynamic-data arbitrary file write via error_loghighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 4 | 0 | |
| 20 Jul 2026 | 2 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 11 | 1 | |
| 24 Aug 2026 | 14 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 7 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/getgrav-grav.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "getgrav/grav (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/getgrav-grav, 26 September 2026.