XSS Vulnerability in Grav Web Platform Prior to Version 2.0.0-beta.2
CVE-2026-42611
8.9HIGH
What is CVE-2026-42611?
The Grav web platform is susceptible to an XSS vulnerability due to improper handling of SVG elements, allowing a low-privileged user to inject harmful scripts. This can lead to significant security risks, including the potential for remote code execution, especially if a Super Admin accesses the compromised page. Users are recommended to update to version 2.0.0-beta.2 or later to mitigate this vulnerability. Stay informed and secure your systems against such attacks.
Affected Version(s)
grav < 2.0.0-beta.2
