Cross-site scripting in Grav CMS - #VU130046
Published: December 10, 2020 / Updated: May 5, 2026
Grav CMS
Grav CMS
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in the Admin plugin page editor when editing pages with the default security configuration. A remote user can inject a crafted script to execute arbitrary code.
Exploitation requires the ability to edit pages and can lead to execution of functionality on behalf of a stolen administrative account, which may then be used to install a custom plugin containing a web shell.