CVE-2026-100673

Source
https://cve.org/CVERecord?id=CVE-2026-100673
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100673.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100673
Aliases
  • GHSA-863q-9v8v-m9fv
Published
2026-09-26T13:23:36Z
Modified
2026-09-28T03:48:32Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
Grav Data Manager before 1.4.5 Stored XSS via item-detail view
Details

The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's raw filter — in some cases after a striptags('
') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor who submits a front-end form whose submissions are saved to user/data can store an HTML payload that executes as JavaScript in the session and origin of an administrator who later opens that entry in the classic admin panel, running with that administrator's privileges and CSRF token. Execution occurs without further interaction for list values (such as checkbox or multi-select fields) and on hover for ordinary text fields. Sites using the Grav 2.0 Admin Next interface are not affected, because it renders the same data through a separate, correctly escaping code path. The issue is fixed in Data Manager 1.4.5.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100673.json"
}
References

Affected packages

Git / github.com/getgrav/grav

Affected ranges

Type
GIT
Repo
https://github.com/getgrav/grav
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.0.1"
        },
        {
            "fixed":  "1.4.5"
        },
        {
            "fixed":  "1.4.4"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100673.json"