CVE-2026-44737

Source
https://cve.org/CVERecord?id=CVE-2026-44737
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44737.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44737
Aliases
Published
2026-05-11T15:52:04.365Z
Modified
2026-07-15T01:49:08.363245917Z
Severity
  • 6.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][title]
Details

grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user input in the data[header][title] parameter. As a result, attackers can craft a malicious URL with an XSS payload. When this URL is accessed, the injected script is reflected back in the HTTP response and executed within the context of the victim's browser session. This vulnerability is fixed in 1.10.49.5.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44737.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/getgrav/grav-plugin-admin

Affected ranges

Type
GIT
Repo
https://github.com/getgrav/grav-plugin-admin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.10.49.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.1.0-beta.1
1.1.0-beta.2
1.1.0-beta.3
1.1.0-beta.4
1.1.0-beta.5
1.1.0-rc.1
1.1.0-rc.2
1.1.0-rc.3
1.1.0-rc.4
1.10.0
1.10.1
1.10.10
1.10.12
1.10.13
1.10.14
1.10.15
1.10.16
1.10.17
1.10.18
1.10.19
1.10.2
1.10.20
1.10.21
1.10.22
1.10.23
1.10.24
1.10.25
1.10.26
1.10.26.1
1.10.27
1.10.28
1.10.29
1.10.3
1.10.30
1.10.30.1
1.10.30.2
1.10.31
1.10.32
1.10.33
1.10.33.1
1.10.34
1.10.35
1.10.36
1.10.37
1.10.37.1
1.10.38
1.10.39
1.10.4
1.10.40
1.10.41
1.10.41.1
1.10.41.2
1.10.42
1.10.43
1.10.44
1.10.45
1.10.46
1.10.47
1.10.48
1.10.49
1.10.49.1
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.2.0-rc.1
1.2.0-rc.2
1.2.12
1.2.13
1.2.14
1.2.5-rc.1
1.2.5-rc.2
1.2.5-rc.3
1.2.5-rc.4
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.8.0
1.8.1
1.8.10
1.8.11
1.8.12
1.8.13
1.8.14
1.8.15
1.8.16
1.8.17
1.8.18
1.8.19
1.8.2
1.8.20
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.10
1.9.12
1.9.13
1.9.14
1.9.15
1.9.16
1.9.17
1.9.18
1.9.19
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44737.json"