← Terug naar overzicht

Grav Shortcode Core versions before 6.2.5 are affected by stored cross-site scripting (XSS) vulnerabilities. The vulnerability exists in the [lorem] tag parameter and [details] summary parameter, which are written to rendered pages without proper HTML escaping. Any attacker with page-edit access can inject arbitrary HTML and JavaScript into page content. The injected scripts execute in the browsers of all visitors who view the affected pages, including administrators. This makes it possible to steal session tokens, perform actions on behalf of admins, or further compromise the site. The issue has been addressed in version 6.2.5 of the Grav Shortcode Core plugin. Users are strongly advised to update immediately. References and advisories are available via GitHub Security Advisories and VulnCheck.

Affected products

  • Grav Shortcode Core

Related CVE's

  • CVE-2026-85599

Categories

  • Web Technologies