Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Grav before version 2.0.15 has a stored cross-site scripting (XSS) vulnerability in the detectXss() function. The flaw allows authenticated editors to inject event-handler attributes such as onerror= by exploiting unpaired quotes in unquoted attribute values, bypassing event-handler detection. This can lead to execution of malicious scripts in visitors' browsers when the affected page content is rendered.
AI Analysis
Technical Summary
The vulnerability exists in Grav CMS versions prior to 2.0.15 within the detectXss() function. It fails to properly detect event-handler attributes when there is an unpaired quote in an unquoted attribute value, allowing authenticated editors to inject event handlers like onerror= that execute stored XSS payloads in visitor browsers. This is a stored XSS vulnerability requiring authenticated editor privileges and involves bypassing input validation due to improper parsing of attribute values.
Potential Impact
Successful exploitation allows authenticated editors to inject malicious event-handler attributes that execute arbitrary JavaScript in the browsers of visitors viewing the affected page content. This can lead to compromise of user sessions, theft of sensitive data, or other client-side impacts. The vulnerability has a high impact on confidentiality and integrity, with no direct impact on availability.
Mitigation Recommendations
A fix is available in Grav version 2.0.15. Users should upgrade to version 2.0.15 or later to remediate this vulnerability. No additional mitigation steps are indicated in the advisory.
Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Description
Grav before version 2.0.15 has a stored cross-site scripting (XSS) vulnerability in the detectXss() function. The flaw allows authenticated editors to inject event-handler attributes such as onerror= by exploiting unpaired quotes in unquoted attribute values, bypassing event-handler detection. This can lead to execution of malicious scripts in visitors' browsers when the affected page content is rendered.
CVSS v3.1
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in Grav CMS versions prior to 2.0.15 within the detectXss() function. It fails to properly detect event-handler attributes when there is an unpaired quote in an unquoted attribute value, allowing authenticated editors to inject event handlers like onerror= that execute stored XSS payloads in visitor browsers. This is a stored XSS vulnerability requiring authenticated editor privileges and involves bypassing input validation due to improper parsing of attribute values.
Potential Impact
Successful exploitation allows authenticated editors to inject malicious event-handler attributes that execute arbitrary JavaScript in the browsers of visitors viewing the affected page content. This can lead to compromise of user sessions, theft of sensitive data, or other client-side impacts. The vulnerability has a high impact on confidentiality and integrity, with no direct impact on availability.
Mitigation Recommendations
A fix is available in Grav version 2.0.15. Users should upgrade to version 2.0.15 or later to remediate this vulnerability. No additional mitigation steps are indicated in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9pr6-8r9w-wvmj
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["Packagist"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6aac8de855bf5e2cf54900d5
Added to database: 09/18/2026, 01:03:36 UTC
Last enriched: 09/18/2026, 01:26:20 UTC
Last updated: 09/18/2026, 01:26:20 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.