getgrav/grav

Licenses: MIT | Unknown

Direct Vulnerabilities

Known vulnerabilities in the getgrav/grav package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Directory Traversal

<2.0.15
  • H
Arbitrary Code Injection

<2.0.15
  • M
Directory Traversal

>=2.0.11, <2.0.13
  • H
Arbitrary Code Injection

<2.0.13
  • M
Origin Validation Error

<2.0.16
  • M
Timing Attack

<1.7.53.3>=1.8.0-beta.1, <2.0.16
  • H
Information Exposure

<2.0.16
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.0.1
  • H
Directory Traversal

<2.0.16
  • M
Regular Expression Denial of Service (ReDoS)

<2.0.4
  • C
Improper Authentication

<2.0.4
  • C
Server-side Request Forgery (SSRF)

<2.0.4
  • H
Information Exposure

<2.0.2
  • M
Cross-site Scripting (XSS)

>=1.5.2, <2.0.13
  • H
Incorrect Authorization

>=2.0.11
  • H
Improper Neutralization of Special Elements Used in a Template Engine

<2.0.13
  • H
Symlink Attack

<2.0.16
  • H
Directory Traversal

<2.0.16
  • H
Arbitrary Code Injection

<2.0.7
  • H
Improper Handling of Case Sensitivity

<2.0.4
  • H
Cross-site Scripting (XSS)

<2.0.15
  • H
Cross-site Scripting (XSS)

<2.0.15
  • M
Cross-site Scripting (XSS)

<2.0.14
  • H
Improper Privilege Management

<2.0.14
  • H
Insufficiently Protected Credentials

<2.0.16
  • H
Insufficiently Protected Credentials

<2.0.16
  • M
Cross-site Scripting (XSS)

<2.0.20
  • M
Incorrect Implementation of Authentication Algorithm

<2.0.9
  • H
Directory Traversal

<2.0.11
  • H
Arbitrary Code Injection

>=2.0.7, <2.0.11
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

>=1.7.0, <2.0.9
  • C
Arbitrary Code Injection

<2.0.7
  • M
Incorrect Implementation of Authentication Algorithm

<2.0.9
  • C
Missing Authorization

>=2.0.3, <2.0.4
  • H
Improper Handling of Case Sensitivity

<2.0.4
  • H
Regular Expression Denial of Service (ReDoS)

<2.0.4
  • M
Insufficient Session Expiration

<2.0.4
  • M
Cross-site Scripting (XSS)

<2.0.1
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.0.2
  • H
Allocation of Resources Without Limits or Throttling

<1.7.53>=2.0.0-beta.1, <2.0.0-rc.8
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

>=1.0.0, <2.0.0
  • H
Arbitrary Code Injection

<2.0.2
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.0.1
  • M
Cross-site Scripting (XSS)

<1.0.3
  • M
Cross-site Scripting (XSS)

>=2.0.0-rc.9, <2.0.0
  • M
Cross-site Scripting (XSS)

<1.6.30
  • M
Insufficiently Protected Credentials

<1.7.53
  • M
Cross-site Scripting (XSS)

<2.0.0-rc.9
  • H
Arbitrary Code Injection

<2.0.0-rc.2
  • M
Cross-site Scripting (XSS)

<1.7.49.5>1.8.0-beta.1, <1.8.0-beta.5
  • H
Arbitrary File Upload

>=0.0.0
  • H
Arbitrary Code Injection

<2.0.0-beta.2
  • H
Incorrect Authorization

<2.0.0-beta.2
  • M
Cross-site Scripting (XSS)

<2.0.0-beta.2
  • C
Deserialization of Untrusted Data

<2.0.0-beta.2
  • H
Cross-site Scripting (XSS)

<2.0.0-beta.2
  • H
Deserialization of Untrusted Data

<2.0.0-beta.2
  • C
Directory Traversal

<2.0.0-beta.2
  • M
Cross-site Scripting (XSS)

<2.0.0-beta.2
  • H
XML External Entity (XXE) Injection

<2.0.0-beta.2
  • C
Improper Input Validation

<2.0.0-beta.2
  • H
Cross-site Scripting (XSS)

<2.0.0-beta.2
  • H
Improper Enforcement of a Single, Unique Action

<2.0.0-beta.2
  • C
Directory Traversal

<2.0.0-beta.2
  • H
XML External Entity (XXE) Injection

>=0.0.0
  • M
Server-side Request Forgery (SSRF)

>=0.8.0
  • M
Cross-site Scripting (XSS)

>=0.8.0
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • H
Improper Authorization

<1.8.0-beta.27
  • H
Improper Neutralization of Special Elements Used in a Template Engine

<1.8.0-beta.27
  • H
Improper Neutralization of Special Elements Used in a Template Engine

<1.8.0-beta.27
  • H
Directory Traversal

<1.8.0-beta.27
  • H
Arbitrary Code Injection

<1.8.0-beta.27
  • H
Arbitrary Code Injection

<1.8.0-beta.27
  • H
Incorrect Privilege Assignment

<1.8.0-beta.27
  • H
Information Exposure

<1.8.0-beta.27
  • M
Directory Traversal

<1.8.0-beta.27
  • M
Uncaught Exception

<1.8.0-beta.27
  • H
Directory Traversal

<1.8.0-beta.27
  • M
Authorization Bypass Through User-Controlled Key

<1.8.0-beta.27
  • M
Denial of Service (DoS)

<1.8.0-beta.27
  • M
Cross-site Scripting (XSS)

>=0.0.0, <1.7.50
  • H
Directory Traversal

<1.7.46
  • M
Cross-site Scripting (XSS)

<1.3.0
  • H
Code Injection

<1.7.45
  • H
Code Injection

<1.7.45
  • H
Improper Control of Generation of Code ('Code Injection')

<1.7.45
  • C
Path Traversal

<1.7.45
  • H
Improper Control of Generation of Code ('Code Injection')

<1.7.45
  • H
Arbitrary File Upload

<1.7.43
  • H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

>=1.7.42.1, <1.7.42.2
  • H
Remote Code Execution (RCE)

<1.7.34
  • H
Improper Input Validation

<1.7.42
  • H
Incomplete List of Disallowed Inputs

<1.7.42
  • C
Arbitrary Code Injection

<1.7.42
  • H
Incomplete List of Disallowed Inputs

<1.7.42
  • C
Code Injection

<1.7.34
  • L
Cross-site Scripting (XSS)

<1.7.33
  • M
Cross-site Scripting (XSS)

<1.7.31
  • M
Cross-site Scripting (XSS)

<1.7.31
  • M
Cross-site Scripting (XSS)

<1.7.28
  • M
Open Redirect

<1.6.23
  • H
Directory Traversal

<1.7.25
  • M
Cross-site Scripting (XSS)

<1.7.24
  • L
Improper Access Control

<1.7.21
  • H
Arbitrary Code Execution

<1.7.11
  • M
Directory Traversal

>=1.7.0-beta.1, <1.7.0-rc.18<1.6.29
  • M
Directory Traversal

>=1.7.0-beta.1, <1.7.0-rc.18<1.6.29
  • M
Cross Site Scripting (XSS)

<1.6.29
  • H
Cross-site Scripting (XSS)

<1.6.30
  • M
Cross-site Scripting (XSS)

>=0.0.0, <1.6.16