CVE-2020-37256
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Jun 25, 2026
Vendor
unknown
Description
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.