CVE-2026-29924

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.
References
Configurations

No configuration.

History

30 Mar 2026, 20:16

Type Values Removed Values Added
CWE CWE-611
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

30 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 19:16

Updated : 2026-03-30 20:16


NVD link : CVE-2026-29924

Mitre link : CVE-2026-29924

CVE.ORG link : CVE-2026-29924


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference