What is CVE-2026-64851?
CVE-2026-64851 is an XSS vulnerability in the Grav Shortcode Core Plugin. Versions prior to 6.2.2 are affected as shortcode syntax bypasses Security::detectXss() due to the absence of a literal less-than character. Update the plugin to version 6.2.2 or later immediately.
Azərbaycanca: CVE-2026-64851 Grav Shortcode Core plaginində XSS zəifliyidir. 6.2.2 versiyasından əvvəlki versiyalar təsirlənir, çünki 'less-than' simvolu olmadığı üçün XSS yoxlamasından yan keçir. Plagin dərhal 6.2.2 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Grav Shortcode Core Plugin are vulnerable to CVE-2026-64851?
All versions prior to 6.2.2 are vulnerable. The plugin should be updated to version 6.2.2 or later immediately.
How does the CVE-2026-64851 vulnerability bypass XSS detection?
The shortcode syntax bypasses `Security::detectXss()` due to the absence of a literal less-than character.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.