Grav

Vendor:

First CVE: Apr 4, 2020 · Active for 6 years

90
Total CVEs
More Total CVEs than 99% of tracked products
12.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Grav over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2020
6 years ago
Most Recent CVE
Jul 23, 2026
4 days ago

CVE Severity & Scoring

Grav90 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network90 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (97.8%)
High2 (2.2%)
Unknown0 (0.0%)
User Interaction
None66 (73.3%)
Unknown0 (0.0%)
Required24 (26.7%)
Privileges Required
Low51 (56.7%)
High12 (13.3%)
None27 (30.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploa
Aug 6, 20258.157NOYES
Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling att
Mar 21, 20248.854NONO
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig proces
Apr 13, 20217.251NOYES
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor perm
Dec 1, 20258.844NOYES
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method cal
Jul 21, 20269.842NONO
Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Sess
Jun 30, 20269.842NONO
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an edi
Dec 1, 20259.642NOYES
The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_
Jul 22, 20268.838NONO
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks
Jul 21, 20269.638NONO
The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The s
Jul 15, 20269.638NONO

Exploit Exposure

Signals from CVEs in this product scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.3% of CVEs· 97th percentile
Nuclei
1 CVE
1.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (90 CVEs).

Media Mentions

Signals from CVEs in this product scope (90 CVEs).

Top CNAs Publishing CVEs For Grav

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.0.097.30.3%00
1.8.0137.70.7%02
1.7.49.516.10.2%00
1.7.4916.10.2%00
1.7.4818.19.3%01
1.7.4516.10.4%00
1.7.42.118.82.8%00
1.7.4218.82.8%00
1.10.719.82.0%00