Vendor
Grav vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 101 vulnerabilities in Grav: 3 in the last 7 days and 85 in the last 90 days, 10 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100672, was published on 26 September 2026. 5 technologies have a page of their own.
- Last 7 days
- 3
- Last 90 days
- 85
- Critical, all time
- 10
- Exploited in the wild
- 0
About Grav
Grav is the developer of an open-source flat-file content management system.
Grav technologies
Latest Grav vulnerabilities
- CVE-2026-100672: Grav Comments plugin unauthenticated information disclosurehighCVSS 7.5
- CVE-2026-100670: Grav CMS blueprint guard bypass privilege escalationhighCVSS 8.8
- CVE-2026-100669: Grav case-insensitive path traversal bypass in access control ruleshighCVSS 7.5
- CVE-2026-75827: Grav Blueprint bare-function arbitrary file write via error_loghighCVSS 8.8EPSS 0.9%
- CVE-2026-74907: Grav path traversal in static asset servermediumCVSS 5.9EPSS 0.4%
- CVE-2026-75831: Grav stored XSS via Markdown audio/video source URLhighCVSS 7.6EPSS 0.4%
- CVE-2026-72832: Grav stored XSS via quoted-attribute bypass in detectXssmediumCVSS 5.4EPSS 0.3%
- CVE-2026-69088: Grav CMS incomplete callable validation in blueprint dynamic fieldshighCVSS 8.1EPSS 0.4%
- CVE-2026-92917: Grav Twig sandbox configuration disclosure via print_rhighCVSS 7.5EPSS 0.5%
- CVE-2026-92916: Grav CMS unauthenticated Clockwork profiler information disclosurehighCVSS 7.5EPSS 0.5%
- CVE-2025-64059: Grav stored cross-site scripting in Home Page editorlowCVSS 1.8EPSS 0.3%
- CVE-2026-86196: Grav API Plugin password reset link spoofing via Host headerinfoCVSS 8.7EPSS 0.4%
- CVE-2026-86194: Grav Form Plugin authorization bypass in cross-page form resolutioninfoCVSS 6.9EPSS 0.6%
- CVE-2026-86193: Grav API Plugin authorization bypass in user-management guardsinfoCVSS 8.7EPSS 0.4%
- CVE-2026-85603: Grav admin plugin path traversal in Save As language parametermediumCVSS 6.5EPSS 0.6%
- CVE-2026-85600: Grav Admin stored XSS in tHtml() via usernamemediumCVSS 5.4EPSS 0.2%
- CVE-2026-85599: Grav Shortcode Core stored XSS in [lorem] and [details] tagshighCVSS 7.2EPSS 0.3%
- CVE-2026-80204: Grav API Plugin scope cap bypass in page permissionsmediumCVSS 5.4EPSS 0.2%
- CVE-2026-80203: Grav API Plugin authorization bypass in user managementcriticalCVSS 9.8EPSS 0.5%
- Grav incomplete Twig sandbox denylist information disclosurehighCVSS 7.5
- Grav UserInterface offsetGet/offsetExists Twig sandbox bypassmediumCVSS 6.5
- Grav path traversal in MediaUploadTrait::deleteFilehighCVSS 8.1
- CVE-2026-76846: Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to…highCVSS 7.5EPSS 0.4%
- CVE-2026-76839: Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and…highCVSS 7.7EPSS 0.5%
- CVE-2026-72702: Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods…mediumCVSS 5.4EPSS 0.1%
Most severe Grav vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-56700: Grav CMS multiple remote code execution vulnerabilitiescriticalCVSS 9.8EPSS 2.5%
- CVE-2026-80203: Grav API Plugin authorization bypass in user managementcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-56710: Grav Login plugin privilege escalation in unlock handlercriticalCVSS 9.8EPSS 0.5%
- CVE-2026-65008: Grav remote code execution in Blueprint dynamicDatacriticalCVSS 9.8
- CVE-2026-65007: Grav api plugin missing authorization in API key generationcriticalCVSS 9.6
- CVE-2026-61451: Grav API plugin password reset token poisoningcriticalCVSS 9.6
- CVE-2026-42613: Grav Login plugin privilege escalation in registration handlercriticalCVSS 9.4EPSS 0.6%
- CVE-2026-42607: Grav Remote Code Execution via Direct Install ZIP uploadcriticalCVSS 9.1EPSS 2.3%
- CVE-2026-42608: Grav Path Traversal and Arbitrary File Write in FormFlashcriticalCVSS 9.1EPSS 0.5%
- CVE-2026-75837: Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super…criticalCVSS 9.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 1 | |
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 15 | 1 | |
| 20 Jul 2026 | 9 | 2 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 13 | 1 | |
| 24 Aug 2026 | 15 | 2 | |
| 31 Aug 2026 | 6 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 7 | 0 | |
| 21 Sep 2026 | 3 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/grav.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Grav vulnerabilities", https://junglewise.ai/threats/vendors/grav, 26 September 2026.