CVE-2026-29924
EUVD-2026-1714830.03.2026, 19:16
Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| getgrav | grav | 𝑥 < 1.8.0 |
𝑥
= Vulnerable software versions
References