Technology · Grav
Grav vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 55 vulnerabilities in Grav: 0 in the last 7 days and 42 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75827, was published on 17 September 2026.
- Last 7 days
- 0
- Last 90 days
- 42
- Critical, all time
- 6
- Exploited in the wild
- 0
About Grav
A flat-file content management system and framework built on Symfony components.
Latest Grav vulnerabilities
- CVE-2026-75827: Grav Blueprint bare-function arbitrary file write via error_loghighCVSS 8.8EPSS 0.9%
- CVE-2026-74907: Grav path traversal in static asset servermediumCVSS 5.9EPSS 0.4%
- CVE-2026-75831: Grav stored XSS via Markdown audio/video source URLhighCVSS 7.6EPSS 0.4%
- CVE-2026-72832: Grav stored XSS via quoted-attribute bypass in detectXssmediumCVSS 5.4EPSS 0.3%
- CVE-2026-69088: Grav CMS incomplete callable validation in blueprint dynamic fieldshighCVSS 8.1EPSS 0.4%
- CVE-2026-92917: Grav Twig sandbox configuration disclosure via print_rhighCVSS 7.5EPSS 0.5%
- CVE-2026-92916: Grav CMS unauthenticated Clockwork profiler information disclosurehighCVSS 7.5EPSS 0.5%
- CVE-2025-64059: Grav stored cross-site scripting in Home Page editorlowCVSS 1.8EPSS 0.3%
- CVE-2026-85603: Grav admin plugin path traversal in Save As language parametermediumCVSS 6.5EPSS 0.6%
- Grav UserInterface offsetGet/offsetExists Twig sandbox bypassmediumCVSS 6.5
- Grav incomplete Twig sandbox denylist information disclosurehighCVSS 7.5
- Grav path traversal in MediaUploadTrait::deleteFilehighCVSS 8.1
- CVE-2026-76846: Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to…highCVSS 7.5EPSS 0.4%
- CVE-2026-76839: Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and…highCVSS 7.7EPSS 0.5%
- CVE-2026-56709: Grav Host header injection in sendInvitationEmailhighCVSS 7.5EPSS 0.4%
- Grav CMS cross-site scripting via Twig sandbox asset injectionmediumCVSS 5.1
- CVE-2026-64850: Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in…highCVSS 8.7EPSS 0.5%
- Grav detectXss stored XSS bypass via unpaired quotehighCVSS 8.7
- Grav Blueprint dynamic-data arbitrary file write via error_loghighCVSS 8.8
- CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-75834: Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function…mediumCVSS 5.4EPSS 0.3%
- Grav stored XSS via quoted-attribute bypass in detectXssmediumCVSS 5.4
- Grav FlexDirectory remote code execution via arbitrary callable executionhighCVSS 8.8
- CVE-2026-65608: Grav remote code execution in FlexDirectory dynamic data fieldshighCVSS 8.8EPSS 1.3%
- CVE-2026-65008: Grav remote code execution in Blueprint dynamicDatacriticalCVSS 9.8
Most severe Grav vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-65008: Grav remote code execution in Blueprint dynamicDatacriticalCVSS 9.8
- CVE-2026-56700: Grav CMS multiple remote code execution vulnerabilitiescriticalCVSS 9.8
- CVE-2026-42613: Grav Login plugin privilege escalation in registration handlercriticalCVSS 9.4
- CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super…criticalCVSS 9.1EPSS 0.5%
- CVE-2026-42608: Grav Path Traversal and Arbitrary File Write in FormFlashcriticalCVSS 9.1
- CVE-2026-42607: Grav Remote Code Execution via Direct Install ZIP uploadcriticalCVSS 9.1
- CVE-2026-42611: Grav stored XSS via SVG tag injection in Admin PluginhighCVSS 8.9
- CVE-2026-65608: Grav remote code execution in FlexDirectory dynamic data fieldshighCVSS 8.8EPSS 1.3%
- CVE-2026-75827: Grav Blueprint bare-function arbitrary file write via error_loghighCVSS 8.8EPSS 0.9%
- CVE-2026-42844: Grav privilege escalation via arbitrary file upload in blueprint-upload APIhighCVSS 8.8EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 1 | |
| 6 Jul 2026 | 8 | 0 | |
| 13 Jul 2026 | 7 | 0 | |
| 20 Jul 2026 | 4 | 1 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 6 | 1 | |
| 24 Aug 2026 | 6 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 7 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/grav.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Grav vulnerabilities", https://junglewise.ai/threats/technologies/grav, 26 September 2026.