Anwendungssicherheit
🟠 CVE-2026-75831: High Schwachstelle
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method....
🟠 CVE-2026-75829: High Schwachstelle
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission to persist...
🟠 CVE-2026-15371: High Schwachstelle
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and...
🟠 CVE-2026-75828: High Schwachstelle
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values...
🟠 CVE-2026-74952: High Luecke in Mozilla Firefox
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
🟠 CVE-2026-74946: High Luecke in Mozilla Firefox
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox...
🟠 CVE-2026-74941: High Luecke in Mozilla Firefox
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1,...
🟠 CVE-2026-75853: High Schwachstelle
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions
🟠 CVE-2026-75836: High Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction()....
🟠 CVE-2026-75827: High Schwachstelle
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist...