getgrav security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect getgrav products.
Vulnios monitors getgrav CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent getgrav security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-66301 — getgrav — grav
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permis
criticalCVE-2025-66301Critical Vulnerability: CVE-2026-42608 — getgrav — grav
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulating the session_id (passed as __form-flash-id in POST
criticalCVE-2026-42608
Track getgrav exposure across your environment
Vulnios automatically cross-references your asset inventory against new getgrav CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan