getgrav/grav Security Advisories for 1.7.36 (13)
-
[HIGH] Grav Vulnerable to Arbitrary File Read to Account Takeover
PKSA-dfbv-gg3q-6zkv CVE-2024-34082 GHSA-f8v5-jmfh-pr69
Affected version: <1.7.46
Reported by:
GitHub -
[HIGH] Server Side Template Injection (SSTI) via Twig escape handler
PKSA-qk36-vv6t-rpy1 CVE-2024-28119 GHSA-2m7x-c7px-hp58
Affected version: <1.7.45
Reported by:
GitHub -
[HIGH] Server Side Template Injection (SSTI)
PKSA-4zrd-fzvb-s4j9 CVE-2024-28118 GHSA-r6vw-8v8r-pmp4
Affected version: <1.7.45
Reported by:
GitHub -
[HIGH] Server Side Template Injection (SSTI)
PKSA-md79-czmr-hzqq CVE-2024-28117 GHSA-qfv4-q44r-g7rv
Affected version: <1.7.45
Reported by:
GitHub -
[HIGH] Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
PKSA-3xkc-2rqf-2zr3 CVE-2024-28116 GHSA-c9gp-64c4-2rrh
Affected version: <1.7.45
Reported by:
GitHub -
[HIGH] Grav File Upload Path Traversal
PKSA-k12q-kcf1-m3gr CVE-2024-27921 GHSA-m7hx-hw6h-mqmc
Affected version: <1.7.45
Reported by:
GitHub -
[CRITICAL] Remote Code Execution by uploading a phar file using frontmatter
PKSA-s32r-k9tt-xp19 CVE-2024-27923 GHSA-f6g2-h7qv-3m5v
Affected version: <1.7.43
Reported by:
GitHub -
[MEDIUM] Cross-site scripting (XSS) vulnerability in Grav
PKSA-b2jk-phpd-zxp3 CVE-2023-31506 GHSA-xrf8-cmrg-7436
Affected version: <1.7.44
Reported by:
GitHub -
[HIGH] grav Server-side Template Injection (SSTI) mitigation bypass
PKSA-dtsr-c39p-kd8y CVE-2023-37897 GHSA-9436-3gmp-4f53
Affected version: <=1.7.42.1
Reported by:
GitHub -
[HIGH] Grav Server-side Template Injection (SSTI) via Twig Default Filters
PKSA-qff4-p3t5-hhpv CVE-2023-34448 GHSA-whr7-m3f8-mpm8
Affected version: <1.7.42
Reported by:
GitHub -
[HIGH] Grav Server-side Template Injection (SSTI) via Denylist Bypass Vulnerability
PKSA-728s-msrd-5k9y CVE-2023-34253 GHSA-j3v8-v77f-fvgm
Affected version: <1.7.42
Reported by:
GitHub -
[HIGH] Grav Server-side Template Injection (SSTI) via Twig Default Filters
PKSA-czz7-ybjd-h94w CVE-2023-34252 GHSA-96xv-rmwj-6p9w
Affected version: <1.7.42
Reported by:
GitHub -
[CRITICAL] Grav Server Side Template Injection (SSTI) vulnerability
PKSA-n6nv-g9gv-59mq CVE-2023-34251 GHSA-f9jf-4cp4-4fq5
Affected version: <1.7.42
Reported by:
GitHub