Vulnerabilities > Getgrav > Low

DATE CVE VULNERABILITY TITLE RISK
2022-04-26 CVE-2022-1173 Cross-site Scripting vulnerability in Getgrav Grav
stored xss in GitHub repository getgrav/grav prior to 1.7.33.
network
getgrav CWE-79
3.5
2022-03-15 CVE-2022-0970 Cross-site Scripting vulnerability in Getgrav Grav
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
network
getgrav CWE-79
3.5
2022-02-28 CVE-2022-0743 Cross-site Scripting vulnerability in Getgrav Grav
Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
network
getgrav CWE-79
3.5
2022-01-25 CVE-2022-0268 Cross-site Scripting vulnerability in Getgrav Grav
Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
network
getgrav CWE-79
3.5
2021-11-19 CVE-2021-3920 Cross-site Scripting vulnerability in Getgrav Grav-Plugin-Admin
grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
getgrav CWE-79
3.5
2021-10-27 CVE-2021-3904 Cross-site Scripting vulnerability in Getgrav Grav
grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
getgrav CWE-79
3.5
2021-03-15 CVE-2020-29556 Path Traversal vulnerability in Getgrav Grav CMS
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files on the underlying server by exploiting a path-traversal technique.
local
low complexity
getgrav CWE-22
2.1