Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/yohane-mashiro/grav

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Grav version 2.0.4 contains a critical remote code execution vulnerability in the Blueprint::dynamicData() function. This flaw allows an authenticated user with admin.pages or api.pages.write permissions to inject malicious callable code into a page. When the page is accessed by any user, including unauthenticated visitors, the injected code executes with the web server's privileges. The vulnerability is fixed in Grav version 2.0.7.

Join the discussion

Grav versions prior to 2.0.16 have a vulnerability due to an incomplete denylist in the Twig sandbox configuration. This flaw allows attackers with page-edit permissions to access sensitive system configuration secrets through Twig template functions like config.get() or config.toArray() when config_access is enabled. The vulnerability can expose secrets such as system.cache.redis.password.

Join the discussion

CVE-2026-76839 is a high-severity vulnerability in Grav versions prior to 2.0.16. It allows sandboxed Twig templates with page-edit permissions to access sensitive User object fields without proper filtering. This flaw exposes hashed passwords and two-factor authentication secrets, potentially enabling offline password cracking and authentication bypass.

Join the discussion
0

Grav CMS versions prior to 2.0.16 have an origin validation bypass vulnerability in the Uri::referrer() and Pages::referrerRoute() methods. The vulnerability arises because the Referer header is validated using an unanchored string prefix match without a trailing delimiter, allowing an attacker controlling a domain starting with the victim's origin to bypass origin checks.

Join the discussion

Grav CMS versions before 2.0.16 have a timing vulnerability in the Utils::verifyNonce() function. This function uses a non-constant-time string comparison (=== operator) instead of a constant-time method like hash_equals() for CSRF nonce validation. Attackers can exploit this by measuring response time differences to recover valid nonce values byte-by-byte, reducing the effectiveness of CSRF protection.

Join the discussion

Grav CMS versions prior to 2.0.16 contain a vulnerability that allows content editors with page-content edit access to read sensitive configuration data. This occurs because the system, site, and theme configuration arrays are not properly filtered in sandboxed Twig template renders. Attackers can exploit this by using dot notation in Twig templates to bypass config_denied_paths restrictions and access secrets such as cache credentials.

Join the discussion

Grav CMS versions before 2.0.16 have a path traversal vulnerability in the media_directory() Twig function. This flaw allows authenticated users with page authoring privileges to supply arbitrary filesystem paths, enabling them to enumerate and read files outside the intended directory scope if those files match configured media extensions accessible by the web server process.

Join the discussion

Grav versions prior to 2.0.16 have a path traversal vulnerability in the MediaUploadTrait::deleteFile() function. Authenticated users with media management permissions can delete arbitrary files outside the intended media directory by using directory traversal sequences in filenames. The vulnerability arises because only the basename of the filename is validated, while directory paths containing '../' sequences are not properly checked before being passed to the unlink() function.

Join the discussion

Grav versions prior to 3.9.2 contain a vulnerability in the sendInvitationEmail() function where untrusted Host headers are not properly validated. This allows attackers to manipulate the Host header to create invitation links that redirect users to attacker-controlled domains. The require_trusted_host protection only applies to password reset flows and does not mitigate this issue for invitation links.

Join the discussion

Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use Grav\Common\Utils::arrayFilterRecursive() as a trampoline with system as the callback, place a command in page frontmatter, and execute that command as the web server user when the page is viewed. This issue is fixed in version 2.0.7.

Join the discussion

Showing 1 to 10 of 85 results

Filters:Package: pkg:github/yohane-mashiro/grav
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses