VulnWatch VulnWatch
← Back to dashboard
Critical github · GHSA-vfmf-q6x9-cw96

Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

Published Sep 17, 2026 CVSS 8.7

Affected versions and vulnerable location

  • Confirmed on grav core at 78ebfc1 (tag 2.0.13).
  • Detector: system/src/Grav/Common/Security.php:290, the on_events regex, run via patternMatches() (:315-330).
  • The on_events pattern at HEAD: `#" onerror=alert(1)> => blocked (on_events) # prior fix works BYPASS A => PASSES (no XSS detected) BYPASS C hover => PASSES (no XSS detected)

Browser tokenization of `

Affected AI Products

replicate
Get the weekly digest. Every Monday: top AI security stories of the week. Free.