Cross-site scripting in Grav CMS - CVE-2026-42841
Published: May 5, 2026
Grav CMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a victim's browser.
The vulnerability exists due to cross-site scripting in the Markdown media action handling for rendered image HTML when processing crafted Markdown image references with media action query parameters. A remote privileged user can store a crafted Markdown image reference that injects an executable event-handler attribute to execute arbitrary JavaScript in a victim's browser.
User interaction is required when another user views the affected page.