Stored XSS Vulnerability in Grav by GetGrav
CVE-2026-85598
5.1MEDIUM
What is CVE-2026-85598?
Versions 2.0.0 through 2.0.17 of Grav exhibit a stored XSS vulnerability due to inadequate save-time XSS detection on modular pages. Authenticated users with page-editing rights can exploit this flaw by injecting malicious Twig code into the modular pages they create. When rendered, this code executes in the browsers of visitors, potentially compromising administrative session security and allowing for unauthorized actions to be taken within the affected system.
Affected Version(s)
grav 2.0.0 <= 2.0.24
