Vendor
high
advisory
Arbitrary File Overwrite in Grav CMS via Symlink Following
1 TTP 1 CVEGrav CMS versions before 2.0.16 are vulnerable to arbitrary file overwrites via a symlink following flaw in the Scheduler component's lock file creation process.
Grav CMS
privilege-escalation
cms
file-write
1t
1c
high
advisory
Authentication Bypass in Grav CMS scheduler-webhook Plugin
1 TTP 1 CVEAn authentication bypass in the Grav CMS scheduler-webhook plugin allows unauthenticated attackers to trigger pre-configured scheduled jobs via the /scheduler/webhook endpoint.
scheduler-webhook
1t
1c
high
advisory
Path Traversal Vulnerability in Grav CMS ImageMedium Class
1 rule 2 TTPs 1 CVEGrav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.
Grav CMS +1
web-vulnerability
twig
information-disclosure
1r
2t
1c
updated