Critical
github
·
GHSA-vfmf-q6x9-cw96
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
Published Sep 17, 2026
CVSS 8.7
Affected versions and vulnerable location
- Confirmed on grav core at
78ebfc1(tag 2.0.13). - Detector:
system/src/Grav/Common/Security.php:290, theon_eventsregex, run viapatternMatches()(:315-330). - The
on_eventspattern at HEAD: `#" onerror=alert(1)> => blocked (on_events) # prior fix works BYPASS A => PASSES (no XSS detected) BYPASS C hover => PASSES (no XSS detected)
Browser tokenization of `
Affected AI Products
replicate