MEDIUMVulnerability
CVE-2026-85598
Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.
Properties
- severity
- MEDIUM
- score
- 6.4
- cve_id
- CVE-2026-85598
- signal_observed_at
- 2026-09-16T01:21:39+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- published_at
- 2026-09-04T12:17:23.340
- last_modified
- 2026-09-14T20:16:58.137
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph