Vulnerabilities > Getgrav > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-14 | CVE-2023-34252 | Code Injection vulnerability in Getgrav Grav Grav is a flat-file content management system. | 7.2 |
2022-06-29 | CVE-2022-2073 | Code Injection vulnerability in Getgrav Grav Code Injection in GitHub repository getgrav/grav prior to 1.7.34. | 7.2 |
2021-11-05 | CVE-2021-3924 | Unspecified vulnerability in Getgrav Grav grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 7.5 |
2021-04-13 | CVE-2021-29440 | Unspecified vulnerability in Getgrav Grav Grav is a file based Web-platform. | 7.2 |
2021-04-13 | CVE-2021-29439 | Unspecified vulnerability in Getgrav Grav Admin The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. | 7.2 |
2021-03-15 | CVE-2020-29553 | Cross-Site Request Forgery (CSRF) vulnerability in Getgrav Grav CMS The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF). | 8.8 |
2021-03-15 | CVE-2020-29555 | Path Traversal vulnerability in Getgrav Grav CMS The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. | 8.1 |