CVE-2026-75828
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like onerror= that pass validation and execute in visitor browsers when page content is rendered.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75828.json, https://github.com/getgrav/grav/security/advisories/GHSA-vfmf-q6x9-cw96, https://nvd.nist.gov/vuln/detail/CVE-2026-75828, https://www.vulncheck.com/advisories/grav-before-stored-xss-via-detectxss-quote-bypass