MEDIUM

CVE-2020-37256

Getgrav Grav 2026-06-25 CVSS v3.1
CVSS
5.4

Description

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.

Summary dbcve.org

Grav CMS before version 1.6.30 has a stored cross-site scripting (XSS) vulnerability in the Admin plugin's page editor default security configuration. This allows privileged users with page editing capabilities to inject malicious JavaScript scripts that can execute arbitrary code on the server and install malicious plugins for persistent system access.

Mitigation

Upgrade Grav to version 1.6.30 or later to obtain the security patch. Review admin user permissions and consider implementing additional input sanitization for the page editor.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.29%
Probability of exploitation in next 30 days
21.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE