Stored Cross-Site Scripting in Grav Shortcode Core by GetGrav
CVE-2026-85599

5.1MEDIUM

Key Information:

Vendor

Getgrav

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85599?

The Grav Shortcode Core, prior to version 6.2.5, is susceptible to stored cross-site scripting (XSS) vulnerabilities. Specifically, the [lorem] tag parameter and the [details] summary parameter allow attackers with page-edit access to inject arbitrary HTML and JavaScript. These scripts run in the browsers of all visitors to the affected pages, including administrators, potentially leading to unauthorized actions or compromise of user data.

Affected Version(s)

grav 0 < 6.2.5

grav 6.2.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.