Composer package intelligence

getgrav/grav Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Composer package getgrav/grav, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting getgrav/grav
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerability absent from CISA KEV
Sensor Observed
0
getgrav/grav KEVs with sensor-observed exploitation activity

Review getgrav/grav exploitation against the versions you run

The single exploited getgrav/grav vulnerability tracked by Previdian is not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested getgrav/grav vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2026-42608

Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

Beyond CISA 27 Sep 2026

Recurring weakness patterns

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') accounts for mapped occurrences across this getgrav/grav KEV portfolio.

Browse all KEVs →