Stored Cross-Site Scripting Vulnerability in Grav by Getgrav
CVE-2026-75828
9.3CRITICAL
What is CVE-2026-75828?
Grav prior to version 2.0.15 is vulnerable to a stored cross-site scripting flaw in the detectXss() function. This vulnerability occurs when unpaired quotes in unquoted attribute values allow authenticated editors to bypass event-handler detection. As a result, malicious event handlers like onerror= can be injected and validated, enabling their execution in the browsers of visitors when pages are rendered. This poses a significant risk, enabling attackers to manipulate user experiences and potentially compromise user data.
Affected Version(s)
grav 0 < 2.0.15
grav 2.0.15
