Vulnerability Description
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
Related Weaknesses (CWE)
References
- https://fluidattacks.com/es/advisories/luis
- https://github.com/getgrav/grav-plugin-api
- https://github.com/getgrav/grav-plugin-api/commit/b8ca62eddb7dbea92075a78b1c0a50
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6
FAQ
What is CVE-2026-11982?
CVE-2026-11982 is a documented vulnerability. Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
How severe is CVE-2026-11982?
CVSS scoring is not yet available for CVE-2026-11982. Check NVD for updates.
Is there a patch for CVE-2026-11982?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.