Impact
Grav versions 2.0.0 through 2.0.17 do not sanitize Twig content when modular pages are saved, permitting authenticated page editors to embed malicious scripts. The stored payload executes in all browsers that render the parent page, including visitor browsers and administrator sessions, leading to potential data theft, defacement, or further compromise of the site.
Affected Systems
The affected vendor is getgrav; the product is Grav CMS. All installations running Grav 2.0.0 up to and including 2.0.17 are vulnerable. No specific sub‑version details beyond this range are available.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium overall risk, and the vulnerability is not listed in the CISA KEV catalog. Exploitability requires authenticated page‑editor privileges; an attacker must have editing rights to inject the payload. While non‑authenticated users cannot exploit directly, once malicious content is stored it can affect any visitor or administrator viewing the page. Due to the lack of an EPSS score, the exact likelihood of exploitation is unknown, but the medium CVSS combined with the necessity of edit permissions limits the threat surface compared to publicly exploitable flaws.
OpenCVE Enrichment