Getgrav maintains a content-management system and associated plugin ecosystem with a modest but notably prominent footprint in the vulnerability landscape, concentrated in its core CMS product and administrative extensions. Vulnerabilities affecting the vendor skew toward meaningful severity outcomes and recur through a durable pattern of input-handling and code-execution weaknesses: cross-site scripting and code-injection flaws in template and request processing, path-traversal conditions in file handling, and privilege-management gaps in the admin layer. The exposure reflects the CMS's exposure to user-supplied content, plugin extensibility, and web-template parsing—a combination that regularly produces output-encoding and injection-related vulnerabilities across this class of software. Defenders deploying Getgrav should prioritize patching of administrative and file-handling components and maintain strict input validation practices; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getgrav over time
Signals from CVEs in this vendor scope (107 CVEs).
107 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21425CRITICAL Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute s | Apr 7, 2021 | 9.8 | 87 | NO | YES |
CVE-2025-50286HIGH A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploa | Aug 6, 2025 | 8.1 | 57 | NO | YES |
CVE-2024-27921HIGH Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling att | Mar 21, 2024 | 8.8 | 54 | NO | NO |
CVE-2021-29440HIGH Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig proces | Apr 13, 2021 | 7.2 | 51 | NO | YES |
CVE-2025-66294HIGH Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor perm | Dec 1, 2025 | 8.8 | 44 | NO | YES |
CVE-2026-65008CRITICAL Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method cal | Jul 21, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-56700CRITICAL Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Sess | Jun 30, 2026 | 9.8 | 42 | NO | NO |
CVE-2025-66301CRITICAL Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an edi | Dec 1, 2025 | 9.6 | 42 | NO | YES |
CVE-2026-65603HIGH The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_ | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-65007CRITICAL The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks | Jul 21, 2026 | 9.6 | 38 | NO | NO |
Signals from CVEs in this vendor scope (107 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getgrav.
Media articles that mention a CVE ID that affects a product developed by Getgrav — matched by CVE ID, not by vendor name.