Grav-Plugin-Admin
Getgrav · 11 CVEs
grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][tit…
May 11, 2026
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `…
Dec 1, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
Dec 1, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]`…
Dec 1, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][i…
Dec 1, 2025
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonom…
Dec 1, 2025
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
Dec 1, 2025
Cross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admin
Nov 19, 2021
Improper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-admin
Sep 27, 2021
Plugins can be installed with minimal admin privileges
Apr 13, 2021
Unauthenticated Arbitrary YAML Write/Update leads to Code Execution
Apr 7, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-44737 | grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][title] | MEDIUM | 0.43% | May 11, 2026 |
| CVE-2025-66312 | Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]` | MEDIUM | 0.21% | Dec 1, 2025 |
| CVE-2025-66311 | Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters | MEDIUM | 0.21% | Dec 1, 2025 |
| CVE-2025-66310 | Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab | MEDIUM | 0.21% | Dec 1, 2025 |
| CVE-2025-66309 | Grav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab | MEDIUM | 0.23% | Dec 1, 2025 |
| CVE-2025-66308 | Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]` | MEDIUM | 0.21% | Dec 1, 2025 |
| CVE-2025-66307 | Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure | MEDIUM | 0.32% | Dec 1, 2025 |
| CVE-2021-3920 | Cross-site Scripting (XSS) - Stored in getgrav/grav-plugin-admin | MEDIUM | 1.37% | Nov 19, 2021 |
| CVE-2021-3799 | Improper Restriction of Rendered UI Layers or Frames in getgrav/grav-plugin-admin | MEDIUM | 1.60% | Sep 27, 2021 |
| CVE-2021-29439 | Plugins can be installed with minimal admin privileges | HIGH | 2.59% | Apr 13, 2021 |
| CVE-2021-21425 | Unauthenticated Arbitrary YAML Write/Update leads to Code Execution | CRITICAL | 80.60% | Apr 7, 2021 |
Showing 1 to 11 of 11 CVEs