CVE Explorer
CVE-2026-44737
grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user input in the data[header][title] parameter. As a result, attackers can craft a malicious URL with an XSS payload. When this URL is accessed, the injected script is reflected back in the HTTP response and executed within the context of the victim's browser sessi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"grav-plugin-admin","vendor":"getgrav","versions":[{"status":"affected","version":"< 1.10.49.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.2,"baseSeverity":"MEDIUM","privilegesRequired":"HIGH","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/getgrav/grav-plugin-admin/commit/f67cc18e81d8767bb43d29ee6422c55ed0427803","tags":["x_refsource_MISC"],"url":"https://github.com/getgrav/grav-plugin-admin/commit/f67cc18e81d8767bb43d29ee6422c55ed0427803"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/getgrav/grav/security/advisories/GHSA-fmg2-f5r9-24qc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/adp/0/references/0
{"name":"https://github.com/getgrav/grav/security/advisories/GHSA-fmg2-f5r9-24qc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/getgrav/grav/security/advisories/GHSA-fmg2-f5r9-24qc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5e80f953a4f67343ceddebbf4a3d02fd88e60de14955206e310df66a87ebc735 · sha256:1153918a6ece3bfa… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.