CVE-2020-36955: Getgrav Grav CMS Admin Plugin
Medium severity, CVSS 6.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
Affected products
- Getgrav Grav CMS Admin Plugin: up to and including 1.9.18
Published 2026-01-26. Last modified 2026-06-17.