Stored Cross-Site Scripting in Grav Shortcode Core by GetGrav
CVE-2026-85599
5.1MEDIUM
What is CVE-2026-85599?
The Grav Shortcode Core, prior to version 6.2.5, is susceptible to stored cross-site scripting (XSS) vulnerabilities. Specifically, the [lorem] tag parameter and the [details] summary parameter allow attackers with page-edit access to inject arbitrary HTML and JavaScript. These scripts run in the browsers of all visitors to the affected pages, including administrators, potentially leading to unauthorized actions or compromise of user data.
Affected Version(s)
grav 0 < 6.2.5
grav 6.2.5
