← Voltar à pesquisa de CVEs

CVE-2026-29924

Grav CMS

Descrição

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

CVSS 7.6EPSS 0.33899999999999997%Risco 0.78
Ver fonte
Publicação
2026-03-30 19:16:24
Versões afetadas
<1.7
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L