What is CVE-2026-64628?
This vulnerability is a stored XSS in Grav's shortcode-core attribute handling, where payloads bypass validation. Users with admin.pages permission can inject malicious JavaScript. Apply the vendor update to affected versions.
Azərbaycanca: Bu boşluq Grav CMS-in shortcode-core funksiyasında saxlanılan XSS zəifliyidir. admin.pages icazəsi olan istifadəçilər skript yeridə bilər. Təsirlənən versiyalara yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
What permissions are required to exploit CVE-2026-64628?
Users with admin.pages permission
See also6
grounded ✓NVD ↗
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.