What is CVE-2026-75831?
Grav CMS versions before 2.0.15 contain a stored XSS vulnerability in the `sourceParsedownElement` method where media URL fragments are unescaped in `rawHtml` source elements. Attackers can inject arbitrary HTML and JavaScript, leading to code execution in users' browsers. Upgrading to the latest version is recommended.
Azərbaycanca: Grav CMS-nin 2.0.15-dən əvvəlki versiyaları audio və video fayllarının göstərilməsində `sourceParsedownElement` metodu vasitəsilə saxlanılan XSS zəifliyi aşkarlanıb. Təcavüzkar media URL-inə xam HTML/JavaScript əlavə edərək istifadəçi brauzerində kod icra edə bilər. Grav-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Grav CMS are affected by the stored XSS vulnerability tracked as CVE-2026-75831?
Grav CMS versions before 2.0.15 are affected by this vulnerability.
What measure should be taken to protect against this vulnerability?
Upgrading Grav to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.