📦 Grav Plugin Admin

by Getgrav

🔍 What is Grav Plugin Admin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-21425

CRITICAL CVSS 9.3 Apr 7, 2021

CVE-2021-21425 is an unauthenticated remote code execution vulnerability in Grav Admin Plugin that allows attackers to execute arbitrary methods without credentials, modify YAML configuration files, a...

CVE-2025-66310

MEDIUM CVSS 5.4 Dec 1, 2025

A stored XSS vulnerability in Grav's admin plugin allows attackers to inject malicious scripts into page templates. These scripts execute automatically when affected content is viewed in the admin int...

CVE-2025-66311

MEDIUM CVSS 5.4 Dec 1, 2025

This stored XSS vulnerability in Grav's admin plugin allows attackers to inject malicious scripts into page metadata fields. When an administrator views or edits an affected page, the scripts execute ...

CVE-2025-66312

MEDIUM CVSS 5.4 Dec 1, 2025

A stored cross-site scripting (XSS) vulnerability in Grav's admin plugin allows attackers to inject malicious scripts into group names. When administrators view the affected groups page, the scripts e...

CVE-2025-66307

MEDIUM CVSS 6.5 Dec 1, 2025

This vulnerability in Grav's admin plugin allows attackers to enumerate valid usernames and discover associated email addresses through the 'Forgot Password' functionality. Attackers can leverage this...

CVE-2025-66308

MEDIUM CVSS 5.4 Dec 1, 2025

A stored XSS vulnerability in Grav's admin plugin allows attackers to inject malicious scripts into the site configuration's taxonomies parameter. The payload persists on the server and executes autom...

CVE-2025-66309

MEDIUM CVSS 6.1 Dec 1, 2025

This reflected XSS vulnerability in Grav's admin plugin allows attackers to inject malicious scripts via the data[header][content][items] parameter in the /admin/pages/[page] endpoint. When exploited,...