CVE-2026-85598
Dashboard / Vulnerabilities / CVE-2026-85598
Summary: Grav 2.0.0 through 2.0.17 Stored XSS via Modular Pages
Details: Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85598.json, https://github.com/getgrav/grav/security/advisories/GHSA-fg8g-663r-f366, https://nvd.nist.gov/vuln/detail/CVE-2026-85598, https://www.vulncheck.com/advisories/grav-2.0.0-through-2.0.17-stored-xss-via-modular-pages
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
