Security: getgrav/grav
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Grav's Clockwork profiler endpoint is unauthenticated: when the debugger is enabled, any visitor can read other users' session cookies, form submissions and the site's plugin configurationGHSA-q3ff-cj6v-rr5g published
Sep 2, 2026 by rhuksterHigh -
Twig content sandbox leaks the full configuration through print_rGHSA-rfr9-7h4p-gx2x published
Sep 2, 2026 by rhuksterHigh -
Target-super guards ignore group-inherited superGHSA-vv8m-jqpm-38x4 published
Aug 21, 2026 by rhuksterHigh -
Cross-page form resolution runs a restricted page's form actions for anonymous visitorsGHSA-33m4-m988-5fvh published
Aug 21, 2026 by rhuksterModerate -
Non-super user manager can mint a super-admin via a dot-keyed super flag in the invitation access payloadGHSA-m363-3hww-gcwc published
Aug 21, 2026 by rhuksterHigh -
Password reset links in the API plugin are built from the request Host header, allowing anonymous account takeoverGHSA-262p-56vv-7v5r published
Aug 21, 2026 by rhuksterHigh -
Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-adminGHSA-8hgv-xc77-jmcr published
Aug 21, 2026 by rhuksterHigh -
Scoped API key can act on super-admin accounts across seven user-management endpointsGHSA-94q7-vrqr-cx5v published
Aug 11, 2026 by rhuksterModerate -
Scoped API key can edit page permissions outside the scope it was grantedGHSA-mcx6-4rvg-7r8v published
Aug 11, 2026 by rhuksterModerate -
Modular pages skip the save-time Twig XSS check, letting a page editor store render-time-assembled stored XSS (incomplete fix for GHSA-2c4f-86xc-cr74)GHSA-fg8g-663r-f366 published
Aug 20, 2026 by rhuksterHigh