References https://nvd.nist.gov/vuln/detail/cve-2024-27921 https://github.com/advisories/GHSA-m7hx-hw6h-mqmc https://advisories.gitlab.com/composer/getgrav/grav/CVE-2024-27921/ https://vulnerability.circl.lu/vuln/gsd-2024-27921 https://tantosec.com/blog/grav/ https://www.cybersecurity-help.cz/vdb/SB2024032222 https://github.com/getgrav/grav/security/advisories/GHSA-m7hx-hw6h-mqmc https://security.snyk.io/vuln/SNYK-PHP-GETGRAVGRAV-6476898 https://advisories.checkpoint.com/defense/advisories/public/2025/cpai-2024-0195.html https://www.miggo.io/vulnerability-database/cve/CVE-2024-27921 https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:DIR:GRAV-CMS-PAGE-MEDIA.html https://socradar.io/free-tools/cve-radar/CVE-2024-27921 https://www.trendmicro.com/vinfo/us/threat-encyclopedia/vulnerability/8881/24-024-may-14-2024
Related VulnerabilitiesPoCCVE-2018-5233: Grav CMS <1.3.0 - Cross-Site ScriptingGrav CMS CVE-2024-28116 服务端模板注入漏洞