Beveiligingsadvies

CVE-2026-85598

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-04 11:30:01
Laatst bijgewerkt 2026-09-05 10:28:16
Toegewezen door VulnCheck
CVSS-score 6.4
Status PUBLISHED

Beschrijving

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.