← Back

CVE-2026-29924

nvd nist
Published: Mar 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Exploitability: 2.8 / Impact: 4.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

Affected (1)

Products: Getgrav: Grav
1 product
Grav
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.8.0

References (1)

Source: cve@mitre.org
Product

Timeline

No history available yet.