getgrav grav

Published Atomicorp research notes for CVEs affecting getgrav grav where WAF protections were observed during testing or engineering review.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

CVEVulnerabilityCVSSSeverityRules Observed
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols9.4 (v4.0)Critical337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-65008Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData9.3 (v4.0)Critical340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()8.7 (v4.0)High340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-69089Grav CMS before 2.0.11 Path Traversal via watermark8.7 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-72819Grav CMS before 2.0.13 Remote Code Execution via ZIP Upload8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72827Grav CMS before 2.0.13 Remote Code Execution via Twig8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass8.7 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twig8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-85604Grav before 2.0.19 Remote Code Execution via sort filter8.7 (v4.0)High340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69088Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint8.6 (v4.0)High340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75833Grav API Plugin Open Redirect via Backslash Bypass8.6 (v4.0)High344365
CVE-2026-62234Grav < 2.0.4 SSRF via Unrestricted cURL Protocols8.4 (v4.0)High337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-74907Grav before 2.0.15 Path Traversal via plugin-asset-map.php8.2 (v4.0)High340007 , 344360 , 347009 , 390709
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile7.1 (v4.0)High344360
CVE-2026-75830grav-plugin-api before 1.0.15 Path Traversal via batchCopy7.1 (v4.0)High340007 , 344360
CVE-2026-64628Grav Stored Cross-Site Scripting via Shortcode Attribute Handlers5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle5.1 (v4.0)Medium333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72832Grav before 2.0.12 Stored XSS via quoted-attribute bypass5.1 (v4.0)Medium333140 , 333141
CVE-2026-74908Grav plugin-api before 1.0.15 Script Injection via SVG5.1 (v4.0)Medium351000
CVE-2026-75831Grav before 2.0.15 Stored XSS via audio/video source URL5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.js5.1 (v4.0)Medium333140
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox5.1 (v4.0)Medium333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148