Vulnerability Description
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Getgrav | Grav | < 1.8.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-29924?
CVE-2026-29924 is a vulnerability with a CVSS score of 7.6 (HIGH). Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
How severe is CVE-2026-29924?
CVE-2026-29924 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29924?
Check the references section above for vendor advisories and patch information. Affected products include: Getgrav Grav.