CVE-2026-29924

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
References
Link Resource
https://github.com/getgrav/grav Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*

History

06 Apr 2026, 15:58

Type Values Removed Values Added
References () https://github.com/getgrav/grav - () https://github.com/getgrav/grav - Product
CPE cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*
First Time Getgrav grav
Getgrav

01 Apr 2026, 14:24

Type Values Removed Values Added
Summary
  • (es) Grav CMS v1.7.x y anteriores es vulnerable a entidad externa XML (XXE) a través de la funcionalidad de carga de archivos SVG en el panel de administración y el plugin File Manager.

30 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-611
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

30 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 19:16

Updated : 2026-04-06 15:58


NVD link : CVE-2026-29924

Mitre link : CVE-2026-29924

CVE.ORG link : CVE-2026-29924


JSON object : View

Products Affected

getgrav

  • grav
CWE
CWE-611

Improper Restriction of XML External Entity Reference