CVE-2026-86197
Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.
| CWE | CWE-79 |
| Vendor | getgrav |
| Product | grav |
| Published | Sep 5, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for getgrav grav
Be the first to know when new unknown vulnerabilities affecting getgrav grav are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
getgrav / grav
0 < 2.0.20
References
Credits
๐ skeletonsec