THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vfmf-q6x9-cw96 (critical) — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

[GHSA] GHSA-vfmf-q6x9-cw96 (critical) — Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

medgithub_advisoriesPublished 2026-09-17

GHSA-vfmf-q6x9-cw96 Severity: critical CVE: CVE-2026-75828

Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

## Affected versions and vulnerable location

- Confirmed on grav core at `78ebfc1` (tag 2.0.13). - Detector: `system/src/Grav/Common/Security.php:290`, the `on_events` regex, run via `patternMatches()` (`:315-330

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vfmf-q6x9-cw96