Grav
Vendor:
First CVE: Apr 4, 2020 · Active for 6 years
90
Total CVEs
More Total CVEs than 99% of tracked products
12.9
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Grav over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 4, 2020
6 years ago
Most Recent CVE
Jul 23, 2026
4 days ago
CVE Severity & Scoring
Grav90 CVEs
39%
50%
11%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network90 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low88 (97.8%)
High2 (2.2%)
Unknown0 (0.0%)
User Interaction
None66 (73.3%)
Unknown0 (0.0%)
Required24 (26.7%)
Privileges Required
Low51 (56.7%)
High12 (13.3%)
None27 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50286HIGH A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the /admin/tools/direct-install interface. Once uploa | Aug 6, 2025 | 8.1 | 57 | NO | YES |
CVE-2024-27921HIGH Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling att | Mar 21, 2024 | 8.8 | 54 | NO | NO |
CVE-2021-29440HIGH Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig proces | Apr 13, 2021 | 7.2 | 51 | NO | YES |
CVE-2025-66294HIGH Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor perm | Dec 1, 2025 | 8.8 | 44 | NO | YES |
CVE-2026-65008CRITICAL Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method cal | Jul 21, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-56700CRITICAL Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Sess | Jun 30, 2026 | 9.8 | 42 | NO | NO |
CVE-2025-66301CRITICAL Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an edi | Dec 1, 2025 | 9.6 | 42 | NO | YES |
CVE-2026-65603HIGH The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_ | Jul 22, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-65007CRITICAL The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks | Jul 21, 2026 | 9.6 | 38 | NO | NO |
CVE-2026-61451CRITICAL The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The s | Jul 15, 2026 | 9.6 | 38 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (90 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.3% of CVEs· 97th percentile
Nuclei
1 CVE
1.1% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (90 CVEs).
Media Mentions
Signals from CVEs in this product scope (90 CVEs).
Top CNAs Publishing CVEs For Grav
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0 | 9 | 7.3 | 0.3% | 0 | 0 |
| 1.8.0 | 13 | 7.7 | 0.7% | 0 | 2 |
| 1.7.49.5 | 1 | 6.1 | 0.2% | 0 | 0 |
| 1.7.49 | 1 | 6.1 | 0.2% | 0 | 0 |
| 1.7.48 | 1 | 8.1 | 9.3% | 0 | 1 |
| 1.7.45 | 1 | 6.1 | 0.4% | 0 | 0 |
| 1.7.42.1 | 1 | 8.8 | 2.8% | 0 | 0 |
| 1.7.42 | 1 | 8.8 | 2.8% | 0 | 0 |
| 1.10.7 | 1 | 9.8 | 2.0% | 0 | 0 |