Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55890 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.0.0-rc.8. | 0.0.0 - 2.0.0-rc.8 | Medium |
CVE-2026-55885 getgrav/grav is vulnerable to Cleartext Storage of Sensitive Information in versions 0.0.0 - 1.7.53. | 0.0.0 - 1.7.53 | Medium |
CVE-2026-44738 getgrav/grav is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 2.0.0-rc.1. | 0.0.0 - 2.0.0-rc.1 | High |
CVE-2026-44737 getgrav/grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.7.49.5. | 0.0.0 - 1.7.49.5 | Medium |
CVE-2026-42844 getgrav/grav is vulnerable to Improper Privilege Management in versions 0.0.0 - 2.0.0-beta.4. | 0.0.0 - 2.0.0-beta.4 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
twig/twig Version 3.x-dev | — | — |
filp/whoops Version ~2.16 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
symfony/yaml Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant