<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:getgrav:shortcode_core:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agetgravshortcode_core/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 13:25:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agetgravshortcode_core/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Grav Shortcode Core</title><link>https://feed.craftedsignal.io/briefs/2026-09-grav-xss/</link><pubDate>Fri, 04 Sep 2026 13:25:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-grav-xss/</guid><description>Grav Shortcode Core versions prior to 6.2.5 are vulnerable to stored cross-site scripting (XSS) due to improper input sanitization in the [lorem] and [details] tags.</description><content:encoded><![CDATA[<p>Grav Shortcode Core, a plugin for the Grav CMS, contains stored cross-site scripting (XSS) vulnerabilities affecting versions prior to 6.2.5. The vulnerability arises from insufficient sanitization of parameters within the [lorem] and [details] shortcodes, which are rendered directly into HTML without proper escaping. An attacker possessing page-editing privileges can inject malicious JavaScript into these tags. When other users or administrators visit the compromised page, the injected payload executes in their browser session. This allows for session hijacking, unauthorized actions performed on behalf of the victim, or credential theft. Given that administrators are susceptible to this attack, successful exploitation could lead to full site compromise if the attacker elevates privileges by targeting a logged-in administrative session.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the execution of arbitrary JavaScript in the browsers of users viewing the injected content. This poses a significant risk to the integrity and confidentiality of the CMS, particularly if administrative users view the compromised pages. It may lead to full site takeover through the unauthorized execution of administrative actions.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for administrators:</p>
<ul>
<li>Upgrade the Grav Shortcode Core plugin to version 6.2.5 or later immediately.</li>
<li>Review all existing content pages for suspicious use of [lorem] or [details] tags if page-editing privileges have been shared with untrusted users.</li>
<li>Audit user roles and permissions to ensure that page-edit capabilities are restricted to authorized personnel.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category></item></channel></rss>