CVE-2026-29924 PUBLISHED

Assigner: mitre
Reserved: 04.03.2026 Published: 30.03.2026 Updated: 30.03.2026

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text