Andy Miller
41 exploits
Active since Apr 2020
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVSS 8.1
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVSS 8.1
Grav: Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
CVSS 9.1
Grav: Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
CVSS 8.1
Grav: Sensitive Information Disclosure via Accounts Service Bypass
CVSS 6.5
Grav: Stored XSS via Tag Injection
CVSS 8.9
Grav: Publisher-Level Stored XSS via Unquoted Event Attributes
CVSS 8.5
Grav: Privilege Escalation via Missing Server-Side Validation of groups/access
CVSS 9.4
Grav: Stored XSS via Markdown media attribute() action in Grav CMS
CVSS 4.8
grav-plugin-form: XSS via Taxonomy Field Values in Admin Panel
CVSS 5.4
Grav: Anonymous Page Content Overwrite via Form File Upload filename Override
grav-plugin-admin: Stored Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][title]
Grav CMS Cache Value FileCache.php doGet deserialization
CVSS 5.0
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
CVSS 4.7
Grav < 1.7 - Open Redirect via Common/Grav.php
CVSS 6.1
Grav < 1.7.42 - Authenticated Remote Code Execution via Template Injection Denylist Bypass
CVSS 8.8
Grav < 1.7.42.2 - Authenticated Server-Side Template Injection via Double Backslash Bypass
CVSS 7.2
DOMSanitizer < 1.0.7 - Cross-Site Scripting via SVG Comment Handling
CVSS 6.1
Grav < 1.7.45 - Path Traversal and Arbitrary File Write via File Upload
CVSS 8.8
Grav < 1.7.43 - Remote Code Execution via Frontmatter Feature
CVSS 8.8
Grav < 1.7.45 - Authenticated Remote Code Execution via Twig Function Bypass
CVSS 8.8
Grav < 1.7.45 - Authenticated Remote Code Execution via Twig Extension Config Redefinition
CVSS 8.8
Grav < 1.7.45 - Authenticated Remote Code Execution via Twig Escape Function Redefinition
CVSS 8.8
Grav < 1.7.46 - Authenticated Arbitrary File Read and Account Takeover via Twig Syntax
CVSS 8.5
Grav <1.8.0-beta.27 - Path Traversal
CVSS 8.8