Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-72832: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getgrav gravCVE-2026-72832
0

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). The event-handler scan is anchored at `<` and uses `[^>]*?`, which cannot cross the first literal `>`; when a `>` appears inside a quoted attribute value the browser keeps the tag open and parses a subsequent event handler (e.g. onerror), so the detector and browser disagree. A page editor without admin.super privileges can save page content such as `<img src=x title=">" onerror=alert(document.domain)>`, which is accepted, stored, and executed in the site origin when any visitor (including unauthenticated users) views the page. Fixed in 2.0.13.

Join the discussion
CVE-2026-72831: Incorrect Authorization in getgrav gravCVE-2026-72831
0

The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and Groups API controllers. An authenticated account with api.access, admin.login, and users.update permissions (but without api.users.write or admin.super) can use the generic /api/v1/flex-objects/user-accounts endpoint to change a super administrator's password, or the /api/v1/flex-objects/user-groups endpoint to grant its group admin.super, resulting in full site takeover. Fixed in Flex Objects 1.4.7.

Join the discussion
CVE-2026-72830: Improper Privilege Management in getgrav gravCVE-2026-72830
0

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

Join the discussion
CVE-2026-72821: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in getgrav gravCVE-2026-72821
0

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the Twig |raw filter. Attackers with form authoring permissions can inject HTML and script payloads in option labels that execute in the browsers of visitors and administrators viewing the form.

Join the discussion
CVE-2026-72820: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in getgrav gravCVE-2026-72820
0

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directories outside GRAV_ROOT when not in the hard-coded deny-list. Attackers with profile editor access can configure backup profiles with traversal paths to expose sensitive files from locations like /opt, /mnt, or /srv.

Join the discussion
CVE-2026-72819: Improper Control of Generation of Code ('Code Injection') in getgrav gravCVE-2026-72819
0

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation, call the unZip routine with a malicious archive, and write PHP files to the web root for execution.

Join the discussion
CVE-2026-69088: Improper Control of Generation of Code ('Code Injection') in getgrav gravCVE-2026-69088
0

Grav CMS versions 2.0.7 through 2.0.10 contain a code injection vulnerability due to improper validation of fully-qualified static method calls in blueprint dynamic-field directives. An attacker with page-editing rights can exploit this flaw to invoke arbitrary public static PHP methods with controlled arguments, enabling reading of any server-readable file and arbitrary file or directory creation under the web server account. This vulnerability is fixed in version 2.0.11.

Join the discussion
CVE-2026-65608: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in getgrav gravCVE-2026-65608
0

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.

Join the discussion
CVE-2026-65008: Improper Control of Generation of Code ('Code Injection') in getgrav gravCVE-2026-65008
0

Grav version 2.0.4 contains a critical remote code execution vulnerability in the Blueprint::dynamicData() function. This flaw allows an authenticated user with admin.pages or api.pages.write permissions to inject malicious callable code into a page. When the page is accessed by any user, including unauthenticated visitors, the injected code executes with the web server's privileges. The vulnerability is fixed in Grav version 2.0.7.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/getgrav/grav
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses