Grav CMS Official Homepageproduct
https://getgrav.org/ CVE-2020-36955
MEDIUM
Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site Scripting
Record summary
CVE-2020-36955 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grav CMS Admin PluginBrowse Getgrav / Grav CMS Admin Plugin | CVE List | Through 1.9.18 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGrav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site ScriptingExploitDB exploitby Sagar BanwaNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36955 ExploitDB-49264exploit
https://www.exploit-db.com/exploits/49264 VulnCheck Advisory: Grav CMS 1.6.30 Admin Plugin 1.9.18 - 'Page Title' Persistent Cross-Site ScriptingThird-party advisory
https://www.vulncheck.com/advisories/grav-cms-admin-plugin-page-title-persistent-cross-site-scripting