THREAT OPS › Threat News › [NVD] CVE-2026-85599 (HIGH 7.2) — Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that ex
[NVD] CVE-2026-85599 (HIGH 7.2) — Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that ex
CVE-2026-85599 CVSS: 7.2 HIGH Published: 2026-09-04T12:17:23.490
Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-85599cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85599