Technology · Getgrav
Getgrav Grav vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in Getgrav Grav: 2 in the last 7 days and 15 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100671, was published on 26 September 2026.
- Last 7 days
- 2
- Last 90 days
- 15
- Critical, all time
- 2
- Exploited in the wild
- 0
Latest Getgrav Grav vulnerabilities
- CVE-2026-100671: Grav session cookie theft via Twig sandboxhighCVSS 8
- CVE-2026-100668: Grav sandbox escape via array filtermediumCVSS 6.5
- CVE-2026-75828: Grav stored XSS in XSS detector via unpaired quote bypasshighCVSS 8.7EPSS 0.4%
- CVE-2026-86197: Grav cross-site scripting in Twig sandbox asset methodsmediumCVSS 4EPSS 0.4%
- CVE-2026-72697: Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-65608: Grav remote code execution in FlexDirectory dynamic data fieldshighCVSS 8.8EPSS 1.3%
- CVE-2026-62237: Grav ReDoS in Twig sandbox regex_replace filtermediumCVSS 6.5EPSS 0.4%
- CVE-2026-62232: Grav Login plugin two-factor authentication bypass in regenerate2FASecrethighCVSS 7.4EPSS 0.4%
- CVE-2026-62230: Grav .htaccess security bypass via case variationhighCVSS 7.5EPSS 0.5%
- CVE-2026-61449: Grav decompression bomb size-cap bypass in ZipArchivermediumCVSS 6.5EPSS 0.4%
- CVE-2026-55890: Grav stored CSS injection in Markdown image style attributemediumCVSS 4.8EPSS 0.3%
- CVE-2026-55885: Grav sensitive data exposure in Admin backup componentmediumCVSS 6.8EPSS 0.3%
- CVE-2026-61455: Grav decompression bomb in ZipArchivermediumCVSS 6.5EPSS 0.4%
- CVE-2026-61450: Grav Twig sandbox bypass in grav.offsetGet methodmediumCVSS 6.5EPSS 0.4%
- CVE-2026-58657: Grav stored CSS injection in Markdown image resize actionmediumCVSS 4.8EPSS 0.4%
- CVE-2026-42844: Grav privilege escalation via arbitrary file upload in blueprint-upload APIhighCVSS 8.8EPSS 0.5%
- CVE-2026-44738: Grav information disclosure via Twig sandbox allow-listhighCVSS 7.7EPSS 0.4%
- CVE-2026-44737: Grav Admin Plugin stored XSS in page move dialogmediumCVSS 4EPSS 0.4%
- CVE-2026-42841: getgrav Grav stored XSS via Markdown media attribute actionmediumCVSS 4.8EPSS 0.3%
- CVE-2026-42612: getgrav Grav stored XSS in detectXss functionhighCVSS 8.5EPSS 0.3%
- CVE-2026-42611: Grav stored XSS via SVG tag injection in Admin PluginhighCVSS 8.9EPSS 0.4%
- CVE-2026-42609: Grav Admin Panel account overwrite via business logic flawhighCVSS 8.1EPSS 0.6%
- CVE-2026-42608: Grav Path Traversal and Arbitrary File Write in FormFlashcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-42607: Grav Remote Code Execution via Direct Install ZIP uploadcriticalCVSS 9.1EPSS 2.3%
Most severe Getgrav Grav vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42607: Grav Remote Code Execution via Direct Install ZIP uploadcriticalCVSS 9.1EPSS 2.3%
- CVE-2026-42608: Grav Path Traversal and Arbitrary File Write in FormFlashcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-42611: Grav stored XSS via SVG tag injection in Admin PluginhighCVSS 8.9EPSS 0.4%
- CVE-2026-65608: Grav remote code execution in FlexDirectory dynamic data fieldshighCVSS 8.8EPSS 1.3%
- CVE-2026-42844: Grav privilege escalation via arbitrary file upload in blueprint-upload APIhighCVSS 8.8EPSS 0.5%
- CVE-2026-75828: Grav stored XSS in XSS detector via unpaired quote bypasshighCVSS 8.7EPSS 0.4%
- CVE-2026-42612: getgrav Grav stored XSS in detectXss functionhighCVSS 8.5EPSS 0.3%
- CVE-2026-42609: Grav Admin Panel account overwrite via business logic flawhighCVSS 8.1EPSS 0.6%
- CVE-2026-100671: Grav session cookie theft via Twig sandboxhighCVSS 8
- CVE-2026-44738: Grav information disclosure via Twig sandbox allow-listhighCVSS 7.7EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 4 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 1 | 0 | |
| 21 Sep 2026 | 2 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/getgrav-grav-1.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Getgrav Grav vulnerabilities", https://junglewise.ai/threats/technologies/getgrav-grav-1, 28 September 2026.