What is CVE-2026-72832?
This vulnerability in Grav CMS versions 1.5.2 through 2.0.12 allows stored cross-site scripting (XSS) attacks due to improper filtering in the `Security::detectXss()` function. Users must upgrade Grav to the latest version immediately.
Azərbaycanca: Bu zəiflik Grav CMS-in 1.5.2-dən 2.0.12-dək versiyalarında stored cross-site scripting (XSS) hücumuna imkan verir. Bu, `Security::detectXss()` funksiyasındakı səhv filtrasiya səbəbindən baş verir. İstifadəçilər dərhal Grav-i ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Grav
FAQ2
What software is affected by CVE-2026-72832?
This vulnerability affects Grav CMS versions 1.5.2 through 2.0.12.
What is the cause of CVE-2026-72832?
The vulnerability allows stored cross-site scripting (XSS) attacks due to improper filtering in the `Security::detectXss()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.