CVE-2026-29924

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
References
Link Resource
https://github.com/getgrav/grav Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-30 19:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29924

Mitre link : CVE-2026-29924

CVE.ORG link : CVE-2026-29924


JSON object : View

Products Affected

getgrav

  • grav
CWE
CWE-611

Improper Restriction of XML External Entity Reference