getgrav/grav Security Advisories for 2.0.15 (8)
-
[HIGH] Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
PKSA-275t-x9d8-k5s3 CVE-2026-72695 GHSA-jq29-c7v8-rg55
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
PKSA-9871-4yy4-mgt8 CVE-2026-72697 GHSA-47ch-6w46-6xm7
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
PKSA-f7gk-wxm8-5j49 CVE-2026-76839 GHSA-3jhr-mxmx-38cx
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
PKSA-rk3g-1sfp-78gs CVE-2026-76846 GHSA-xjw5-q542-3vmr
Affected version: <=2.0.15
Reported by:
GitHub -
[HIGH] Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
PKSA-wz98-fgrh-3wq2 CVE-2026-72698 GHSA-p597-crqc-m349
Affected version: <2.0.16
Reported by:
GitHub -
[LOW] Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
PKSA-xzd7-91fp-yh97 CVE-2026-72701 GHSA-38p6-h87p-r4cg
Affected version: <=2.0.15
Reported by:
GitHub -
[LOW] Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
PKSA-ms14-tz6x-6sqm CVE-2026-72702 GHSA-9ccq-2jfg-qw33
Affected version: <=2.0.15
Reported by:
GitHub -
[MEDIUM] Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
PKSA-rjzr-vkvg-cvmf GHSA-8hgv-xc77-jmcr
Affected version: <=2.0.19
Reported by:
GitHub