{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/shortcode-core--6.2.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:getgrav:shortcode_core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-85599"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Shortcode Core (\u003c 6.2.5)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Grav"],"content_html":"\u003cp\u003eGrav Shortcode Core, a plugin for the Grav CMS, contains stored cross-site scripting (XSS) vulnerabilities affecting versions prior to 6.2.5. The vulnerability arises from insufficient sanitization of parameters within the [lorem] and [details] shortcodes, which are rendered directly into HTML without proper escaping. An attacker possessing page-editing privileges can inject malicious JavaScript into these tags. When other users or administrators visit the compromised page, the injected payload executes in their browser session. This allows for session hijacking, unauthorized actions performed on behalf of the victim, or credential theft. Given that administrators are susceptible to this attack, successful exploitation could lead to full site compromise if the attacker elevates privileges by targeting a logged-in administrative session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the execution of arbitrary JavaScript in the browsers of users viewing the injected content. This poses a significant risk to the integrity and confidentiality of the CMS, particularly if administrative users view the compromised pages. It may lead to full site takeover through the unauthorized execution of administrative actions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Grav Shortcode Core plugin to version 6.2.5 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview all existing content pages for suspicious use of [lorem] or [details] tags if page-editing privileges have been shared with untrusted users.\u003c/li\u003e\n\u003cli\u003eAudit user roles and permissions to ensure that page-edit capabilities are restricted to authorized personnel.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T13:25:50Z","date_published":"2026-09-04T13:25:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-grav-xss/","summary":"Grav Shortcode Core versions prior to 6.2.5 are vulnerable to stored cross-site scripting (XSS) due to improper input sanitization in the [lorem] and [details] tags.","title":"Stored Cross-Site Scripting in Grav Shortcode Core","url":"https://feed.craftedsignal.io/briefs/2026-09-grav-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Shortcode Core (\u003c 6.2.5)","version":"https://jsonfeed.org/version/1.1"}