What is CVE-2026-75828?
CVE-2026-75828 is a stored cross-site scripting vulnerability in the detectXss() function of Grav CMS before version 2.0.15. Authenticated editors can bypass validation by using unpaired quotes in unquoted attributes to inject event handlers, which then execute in visitors' browsers. Update Grav to version 2.0.15 or later to mitigate the issue.
Azərbaycanca: CVE-2026-75828, Grav CMS-in 2.0.15-dən əvvəlki versiyalarında detectXss() funksiyasında saxlanılan XSS zəifliyidir. Bu zəiflik autentifikasiya olunmuş redaktorlara xüsusi simvollar vasitəsilə event handler-lər yeridərək istifadəçi brauzerlərində kod icra etməyə imkan verir. Grav-i ən azı 2.0.15 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Grav CMS are affected by CVE-2026-75828?
The vulnerability affects Grav CMS versions prior to 2.0.15.
To what version should Grav CMS be updated to protect against CVE-2026-75828?
It is recommended to update Grav CMS to version 2.0.15 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.