Stored Cross-Site Scripting Vulnerability in Grav Web Platform
CVE-2026-42612
8.5HIGH
What is CVE-2026-42612?
Grav, a file-based web platform, has a stored Cross-Site Scripting vulnerability that allows publisher-level accounts to execute arbitrary JavaScript. This security issue is due to a blacklist bypass in the detectXss() function when it processes unquoted HTML event attributes. The vulnerability impacts versions before 2.0.0-beta.2, and users are encouraged to update to the latest version to mitigate the risk.
Affected Version(s)
grav < 2.0.0-beta.2
