getgrav grav
Published Atomicorp research notes for CVEs affecting getgrav grav where WAF protections were observed during testing or engineering review.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
| CVE | Vulnerability | CVSS | Severity | Rules Observed |
|---|---|---|---|---|
| CVE-2026-62668 | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | 9.4 (v4.0) | Critical | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-65008 | Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData | 9.3 (v4.0) | Critical | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | 8.7 (v4.0) | High | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-69089 | Grav CMS before 2.0.11 Path Traversal via watermark | 8.7 (v4.0) | High | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-72819 | Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload | 8.7 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72827 | Grav CMS before 2.0.13 Remote Code Execution via Twig | 8.7 (v4.0) | High | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-72830 | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | 8.7 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75574 | Grav before 4.2.2 Remote Code Execution via Email Twig | 8.7 (v4.0) | High | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-85604 | Grav before 2.0.19 Remote Code Execution via sort filter | 8.7 (v4.0) | High | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-69088 | Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint | 8.6 (v4.0) | High | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75833 | Grav API Plugin Open Redirect via Backslash Bypass | 8.6 (v4.0) | High | 344365 |
| CVE-2026-62234 | Grav < 2.0.4 SSRF via Unrestricted cURL Protocols | 8.4 (v4.0) | High | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-74907 | Grav before 2.0.15 Path Traversal via plugin-asset-map.php | 8.2 (v4.0) | High | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-72695 | Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile | 7.1 (v4.0) | High | 344360 |
| CVE-2026-75830 | grav-plugin-api before 1.0.15 Path Traversal via batchCopy | 7.1 (v4.0) | High | 340007 , 344360 |
| CVE-2026-64628 | Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers | 5.1 (v4.0) | Medium | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72821 | Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle | 5.1 (v4.0) | Medium | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72832 | Grav before 2.0.12 Stored XSS via quoted-attribute bypass | 5.1 (v4.0) | Medium | 333140 , 333141 |
| CVE-2026-74908 | Grav plugin-api before 1.0.15 Script Injection via SVG | 5.1 (v4.0) | Medium | 351000 |
| CVE-2026-75831 | Grav before 2.0.15 Stored XSS via audio/video source URL | 5.1 (v4.0) | Medium | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85601 | Grav Admin before 2.0.20 Cross-Site Scripting via marked.js | 5.1 (v4.0) | Medium | 333140 |
| CVE-2026-86197 | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox | 5.1 (v4.0) | Medium | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |