๐Ÿ” CVE Alert

CVE-2026-85599

HIGH 7.2

Grav Shortcode Core before 6.2.5 Stored XSS via unescaped parameters

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.

CWE CWE-79
Vendor getgrav
Product grav
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for getgrav grav

Be the first to know when new high vulnerabilities affecting getgrav grav are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

getgrav / grav
0 < 6.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/getgrav/grav/security/advisories/GHSA-hvm8-wx3f-j774 vulncheck.com: https://www.vulncheck.com/advisories/grav-shortcode-core-before-6.2.5-stored-xss-via-unescaped-parameters