51 Total CVEs
51 AI Analyzed
0 CISA KEV
11 Critical

Profile

0% ended up actively exploited 0 of 51 added to CISA KEV
22% rated critical (CVSS 9.0+) 11 critical, 40 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

51 CVEs in the last 12 months

Products

  • grav18
  • Grav9
  • Grav CMS6
  • API Plugin2
  • grav-plugin-api2
  • grav-plugin-login1
  • grav (Grav API plugin)1
  • Grav Admin Plugin1

10 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-51 of 51 CVEs
CVE-2026-85604
Analyzed
8.8
getgrav Grav CMS

Grav before 2.0.19 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravE...

2026-09-05 Patch
CVE-2026-80203
Analyzed
9.8
getgrav Grav

The Grav API plugin fails to properly validate API key scopes within its user management endpoints, allowing restricted API keys to perform unauthoriz...

2026-08-27
CVE-2026-76846
Analyzed
7.5
getgrav Grav

Grav before 2

2026-08-25
CVE-2026-75574
Analyzed
8.8
getgrav Grav

The Grav Email plugin (getgrav/grav-plugin-email) before 4

2026-08-25
CVE-2026-72833
Analyzed
8.8
getgrav Grav

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1

2026-08-15
CVE-2026-72831
Analyzed
8.8
getgrav grav

The Flex Objects plugin (through 1

2026-08-15
CVE-2026-72830
Analyzed
9.8
getgrav grav

The Grav API plugin fails to enforce API key scopes in the ConfigController, allowing attackers to inject and execute arbitrary OS commands via the sc...

2026-08-15
CVE-2026-72829
Analyzed
9.8
getgrav grav

The Grav API plugin contains a flaw in UsersController that allows attackers to bypass scope caps and promote accounts to super-user status.

2026-08-15
CVE-2026-72828
Analyzed
7.2
getgrav grav

Grav Plugin API (getgrav/grav-plugin-api) before 1

2026-08-16
CVE-2026-72827
Analyzed
8.8
getgrav Grav CMS

Grav CMS before 2

2026-08-15
CVE-2026-72826
Analyzed
9.8
getgrav grav

The getgrav grav-plugin-api fails to validate API key scopes during creation, allowing attackers to mint unauthorized, full-access super keys.

2026-08-15
CVE-2026-72825
Analyzed
7.6
getgrav grav

The getgrav/grav-plugin-api plugin before 1

2026-08-16
CVE-2026-72824
Analyzed
9.8
getgrav grav

The Grav API plugin contains an authorization bypass in PagesController that allows unauthenticated attackers to achieve server-side template injectio...

2026-08-15
CVE-2026-72822
Analyzed
9.8
getgrav grav

A critical authentication bypass vulnerability in the getgrav/grav-plugin-api package allows unauthorized users to disable two-factor authentication o...

2026-08-15
CVE-2026-72819
Analyzed
8.8
getgrav Grav CMS

Grav CMS before 2

2026-08-15
CVE-2026-72700
Analyzed
7.5
getgrav grav-plugin-login

The getgrav/grav-plugin-login Composer plugin before 3

2026-08-25
CVE-2026-72696
Analyzed
8.4
getgrav Grav CMS

Grav CMS before 2

2026-08-25
CVE-2026-72695
Analyzed
8.1
getgrav Grav

Grav before 2

2026-08-25
CVE-2026-69089
Analyzed
7.5
getgrav grav

Grav CMS 2

2026-08-04
CVE-2026-69088
Analyzed
8.1
getgrav grav

Grav CMS versions 2

2026-08-04
CVE-2026-65897
Analyzed
8.8
getgrav API Plugin

Grav API Plugin versions before 1

2026-07-24
CVE-2026-65895
Analyzed
8.5
getgrav API Plugin

Grav API Plugin versions before 1

2026-07-24
CVE-2026-65608
Analyzed
8.8
getgrav Grav

Grav versions >= 1

2026-07-24
CVE-2026-65603
Analyzed
8.8
getgrav grav

The Grav Login plugin (grav-plugin-login) versions <= 3

2026-07-23
CVE-2026-64852
Analyzed
8.7
getgrav grav-plugin-api

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

2026-08-21
CVE-2026-64850
Analyzed
8.7
getgrav grav

Grav is a file-based Web platform

2026-08-21
CVE-2026-62666
Analyzed
8.8
getgrav grav-plugin-api

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

2026-08-20
CVE-2026-62234
Analyzed
8.1
getgrav grav

Grav before 2

2026-07-17
CVE-2026-62233
Analyzed
8.8
getgrav grav

grav-plugin-api before 1

2026-07-17
CVE-2026-62231
Analyzed
8.1
getgrav grav (Grav API plugin)

The Grav API plugin (getgrav/grav-plugin-api) before 1

2026-07-17
CVE-2026-61457
Analyzed
8.8
getgrav grav

The Grav API plugin (getgrav/grav-plugin-api) before 1

2026-07-16
CVE-2026-61451
Analyzed
9.6
getgrav grav

The Grav API plugin is vulnerable to an open redirect during password reset, allowing attackers to hijack reset tokens and perform full account takeov...

2026-07-16
CVE-2026-59190
Analyzed
8.7
getgrav Grav Admin Plugin

grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages

2026-07-11
CVE-2026-58655
Analyzed
8.8
getgrav Grav

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1

2026-07-16
CVE-2026-58492
Analyzed
9.2
getgrav grav

The grav-plugin-database for Grav CMS is vulnerable to SQL injection via the PDO::tableExists method due to improper input sanitization.

2026-07-11
CVE-2026-56710
Analyzed
9.8
getgrav grav

The Grav Login plugin before 1.0.16 fails to validate privilege levels in the API, allowing attackers to remove brute-force protection from high-privi...

2026-08-25
CVE-2026-56709
Analyzed
7.5
getgrav Grav

Grav before 3

2026-08-25
CVE-2026-56707
Analyzed
7.7
getgrav Grav Flex Objects plugin

Grav Flex Objects plugin versions 1

2026-08-25
CVE-2026-53653
Analyzed
8.7
getgrav Grav

Grav is a file-based Web platform

2026-07-11
CVE-2026-44738
Analyzed
7.7
getgrav keys

Grav is a file-based Web platform

2026-05-12
CVE-2026-42843
Analyzed
8.8
getgrav Multiple Products

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system manag...

2026-05-12
CVE-2026-42613
Analyzed
9.4
getgrav Grav CMS

Grav CMS is vulnerable to an authentication bypass during user registration, allowing an unauthenticated user to assign themselves administrative priv...

2026-05-12
CVE-2026-42612
Analyzed
8.5
getgrav Multiple Products

Grav is a file-based Web platform

2026-05-12
CVE-2026-42611
Analyzed
8.9
getgrav Multiple Products

Grav is a file-based Web platform

2026-05-12
CVE-2026-42609
Analyzed
8.1
getgrav Multiple Products

Grav is a file-based Web platform

2026-05-12
CVE-2026-42607
Analyzed
9.1
getgrav Grav CMS

Grav CMS allows authenticated administrators to achieve Remote Code Execution (RCE) by uploading malicious ZIP files via the "Direct Install" tool.

2026-05-12
CVE-2025-66300
Analyzed
8.5
getgrav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66299
Analyzed
8.8
getgrav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66296
Analyzed
8.8
getgrav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2025-66295
Analyzed
8.8
getgrav Multiple Products

Grav is a file-based Web platform

2025-12-02
CVE-2021-47812
Analyzed
7.5
getgrav Multiple Products

GravCMS 1

2026-01-16