CVE-2026-85598 Details
Description
Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.
A stored cross-site scripting vulnerability has been identified in Grav versions 2.0.0 through 2.0.17. This issue arises because the save-time XSS detection does not apply to modular pages, allowing authenticated page editors to save Twig-generated XSS payloads. When the parent page is rendered, these payloads execute in the browsers of visitors, including administrators.
Users can upgrade to Grav 2.0.18, where this vulnerability is fixed. For unpatched installs, it is recommended to restrict page-edit permissions to trusted accounts or ensure that modular templates do not use raw output.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/security/advisories/GHSA-fg8g-663r-f366 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/grav-2.0.0-through-2.0.17-stored-xss-via-modular-pages | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav | >= 2.0.0, <= 2.0.17 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2026 | CVE Modified | [email protected] |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion