5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Description
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
Basic Information
ID
CVE-2026-11982
Source
Fluid Attacks
Published
Jun 18, 2026 at 16:22
Modified
Jun 18, 2026 at 17:26
Affected Product
Vendor
Grav
Product
grav-plugin-api
Version
1.7.52
Affected Versions
Grav grav-plugin-api 1.7.52