CVE Tools

Getgrav

169 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.

Getgrav CVEs per month

Apr 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Getgrav CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0430
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0650
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-0360
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12220
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05140
2026-06null or fewer
2026-07380
2026-08660
2026-09150

Products

The products that kept showing up in Getgrav's monthly top three, with their CVEs summed over those months.

  1. Grav1468 months
  2. Grav-plugin-api102 months
  3. Grav-plugin-admin93 months
  4. Grav-plugin-form42 months
  5. Grav-plugin-login31 month
  6. Grav Admin11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Getgrav.

  1. CVE-2026-100673Grav Data Manager before 1.4.5 Stored XSS via item-detail view8.2
  2. CVE-2026-100672grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure7.5
  3. CVE-2026-100671Grav before 2.0.25 Session Cookie Theft via Twig Sandbox8.0
  4. CVE-2026-100670Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass8.8
  5. CVE-2026-100669Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass7.5
  6. CVE-2026-100668Grav before 2.0.25 Sandbox Escape via array Filter6.5
  7. CVE-2026-100667grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass5.3
  8. CVE-2026-92917Grav 2.0.0-rc.1 through 2.0.21 Configuration Disclosure via print_r7.5
  9. CVE-2026-92916Grav through 2.0.21 Unauthenticated Information Disclosure via Clockwork7.5
  10. CVE-2025-64059Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and...1.8
  11. CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox—
  12. CVE-2026-86196Grav API Plugin before 1.0.20 Authentication Bypass via Host Header—
  13. CVE-2026-86194Grav Form Plugin before 9.1.22 Cross-Page Form Execution—
  14. CVE-2026-86195grav-plugin-api 1.0.0 through 1.0.19 Privilege Escalation via Dot-Keyed Super Flag—
  15. CVE-2026-86193Grav API Plugin Authentication Bypass via Group-Inherited Super—

The record

Peak rank
#14 in Aug 2026
Busiest month shown
Aug 2026, 66 CVEs
Months with a KEV entry
0 since Apr 2021
Monthly snapshots
8 since 2021
Getgrav's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store