CVE-2026-85599: Getgrav Grav-Plugin-Shortcode-Core
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.
Affected products
- Getgrav Grav-Plugin-Shortcode-Core: before 6.2.5 (fixed in 6.2.5)
Published 2026-09-04. Last modified 2026-09-08.