CVE-2026-100673: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getgrav grav
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5.
AI Analysis
Technical Summary
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 improperly neutralize input during web page generation by rendering stored data entries with Twig's `raw` filter after a PHP strip_tags('<br>') call that allows certain HTML tags and attributes to bypass filtering. An unauthenticated user can submit a front-end form with malicious HTML/JavaScript payloads saved to user data. When an administrator later views these entries in the classic admin panel (admin/templates/partials/item.html.twig), the payload executes with the administrator's privileges and CSRF token. Execution is automatic for list values and occurs on hover for text fields. The Grav 2.0 Admin Next interface is not affected due to a different, secure rendering method. The vulnerability is resolved in Data Manager version 1.4.5.
Potential Impact
An unauthenticated attacker can inject and store malicious HTML/JavaScript that executes in the context of an administrator's session and privileges when the admin views the stored data in the classic admin panel. This can lead to unauthorized actions performed with the admin's credentials and CSRF token, potentially compromising the site integrity and security. The vulnerability does not require user interaction for some field types, increasing risk.
Mitigation Recommendations
Upgrade the Grav Data Manager plugin to version 1.4.5 or later, where this vulnerability is fixed. Sites using the Grav 2.0 Admin Next interface are not affected by this issue. No other mitigations are indicated by the vendor advisory.
CVE-2026-100673: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getgrav grav
Description
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5.
CVSS v4.0
Score 8.4high
Affected software
getgrav
grav
pkg:github/getgrav/grav-data-managerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 improperly neutralize input during web page generation by rendering stored data entries with Twig's `raw` filter after a PHP strip_tags('<br>') call that allows certain HTML tags and attributes to bypass filtering. An unauthenticated user can submit a front-end form with malicious HTML/JavaScript payloads saved to user data. When an administrator later views these entries in the classic admin panel (admin/templates/partials/item.html.twig), the payload executes with the administrator's privileges and CSRF token. Execution is automatic for list values and occurs on hover for text fields. The Grav 2.0 Admin Next interface is not affected due to a different, secure rendering method. The vulnerability is resolved in Data Manager version 1.4.5.
Potential Impact
An unauthenticated attacker can inject and store malicious HTML/JavaScript that executes in the context of an administrator's session and privileges when the admin views the stored data in the classic admin panel. This can lead to unauthorized actions performed with the admin's credentials and CSRF token, potentially compromising the site integrity and security. The vulnerability does not require user interaction for some field types, increasing risk.
Mitigation Recommendations
Upgrade the Grav Data Manager plugin to version 1.4.5 or later, where this vulnerability is fixed. Sites using the Grav 2.0 Admin Next interface are not affected by this issue. No other mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:34:55.635Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9abf7a7c5410652fd4a
Added to database: 09/26/2026, 13:33:31 UTC
Last enriched: 09/26/2026, 13:48:49 UTC
Last updated: 09/27/2026, 01:57:11 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.