Andy Miller
41 exploits
Active since Apr 2020
Grav <1.8.0-beta.27 - Privilege Escalation
CVSS 8.8
Grav <1.8.0-beta.27 - RCE/Privilege Escalation
CVSS 8.8
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 7.5
Grav < 1.8.0-beta.27 - Authenticated Server-Side Template Injection via Twig Directive Manipulation
CVSS 8.8
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 8.5
Grav <1.8.0-beta.27 - Path Traversal
CVSS 6.8
Grav < 1.8.0-beta.27 - Denial of Service via Scheduled_at Parameter
CVSS 4.9
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 6.2
Grav < 1.8.0-beta.27 - Denial of Service via Malformed Supported Parameter in Admin Configuration
CVSS 4.9
Grav <1.8.0-beta.27 - Info Disclosure
CVSS 4.3
Grav <1.11.0-beta.1 - Info Disclosure
CVSS 6.5
Grav Admin Plugin < 1.11.0-beta.1 - Stored Cross-Site Scripting via data[taxonomies] Parameter
CVSS 5.4
Grav Admin Plugin < 1.11.0-beta.1 - Reflected Cross-Site Scripting via data[header][content][items] Parameter
CVSS 6.1
Grav Admin Plugin < 1.10.50 - Stored Cross-Site Scripting via data[header][template] Parameter
CVSS 5.4
Grav Admin Plugin < 1.11.0-beta.1 - Stored Cross-Site Scripting via Page Metadata Parameters
CVSS 5.4
Grav Admin Plugin < 1.10.50 - Stored Cross-Site Scripting via data[readableName] Parameter
CVSS 5.4