← Volver al buscador de CVEs

CVE-2026-44737

grav-plugin-admin

Descripción

grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user input in the data[header][title] parameter. As a result, attackers can craft a malicious URL with an XSS payload. When this URL is accessed, the injected script is reflected back in the HTTP response and executed within the context of the victim-s browser session. This vulnerability is fixed in 1.10.49.5.

CVSS 6.2EPSS 0.256%Riesgo 0.63
Ver fuente
Publicación
2026-05-11 17:16:34
Versiones afectadas
<1.10.49.5
Tipo
Core software
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X