SB20260507107 - Cross-site scripting in Grav Admin Plugin
Published: May 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cross-site scripting (CVE-ID: N/A)
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the /admin/pages/[page] endpoint when handling the data[header][title] parameter. A remote privileged user can inject a crafted script payload to execute arbitrary script in the victim's browser.
User interaction is required when a victim accesses the crafted URL or clicks the folder containing the payload in the move function.
Remediation
Install update from vendor's website.