CVE-2026-85599: Getgrav Grav-Plugin-Shortcode-Core

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.

Affected products

  • Getgrav Grav-Plugin-Shortcode-Core: before 6.2.5 (fixed in 6.2.5)

Published 2026-09-04. Last modified 2026-09-08.