Stored XSS Vulnerability in Grav by GetGrav
CVE-2026-85598

5.1MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85598?

Versions 2.0.0 through 2.0.17 of Grav exhibit a stored XSS vulnerability due to inadequate save-time XSS detection on modular pages. Authenticated users with page-editing rights can exploit this flaw by injecting malicious Twig code into the modular pages they create. When rendered, this code executes in the browsers of visitors, potentially compromising administrative session security and allowing for unauthorized actions to be taken within the affected system.

Affected Version(s)

grav 2.0.0 <= 2.0.24

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TWPaMWang
.