Vulnerabilities > Getgrav > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-09 | CVE-2023-31506 | Cross-site Scripting vulnerability in Getgrav Grav A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover attribute of an ISINDEX element. | 5.4 |
2023-11-22 | CVE-2023-49146 | Cross-site Scripting vulnerability in Getgrav Dom-Sanitizer DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions. | 6.1 |
2023-06-14 | CVE-2023-34452 | Cross-site Scripting vulnerability in Getgrav Grav Grav is a flat-file content management system. | 6.1 |
2022-06-29 | CVE-2022-2073 | Code Injection vulnerability in Getgrav Grav Code Injection in GitHub repository getgrav/grav prior to 1.7.34. | 6.5 |
2021-11-05 | CVE-2021-3924 | Path Traversal vulnerability in Getgrav Grav grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | 5.0 |
2021-09-27 | CVE-2021-3799 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Getgrav Grav-Plugin-Admin grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames | 5.8 |
2021-09-27 | CVE-2021-3818 | Reliance on Cookies without Validation and Integrity Checking vulnerability in Getgrav Grav grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking | 5.0 |
2021-03-15 | CVE-2020-29553 | Cross-Site Request Forgery (CSRF) vulnerability in Getgrav Grav CMS The Scheduler in Grav CMS through 1.7.0-rc.17 allows an attacker to execute a system command by tricking an admin into visiting a malicious website (CSRF). | 5.1 |
2021-03-15 | CVE-2020-29555 | Path Traversal vulnerability in Getgrav Grav CMS The BackupDelete functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to delete arbitrary files on the underlying server by exploiting a path-traversal technique. | 5.5 |
2020-04-04 | CVE-2020-11529 | Open Redirect vulnerability in Getgrav Grav Common/Grav.php in Grav before 1.7 has an Open Redirect. | 5.8 |