CVE-2026-11982
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jun 18, 2026
Vendor
unknown
Description
Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages API save flow.
References
- https://fluidattacks.com/es/advisories/luis
- https://github.com/getgrav/grav-plugin-api
- https://github.com/getgrav/grav-plugin-api/commit/b8ca62eddb7dbea92075a78b1c0a507f03d66d4a
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6
- https://github.com/getgrav/grav/security/advisories/GHSA-5wc5-7v9g-f7v6