Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/getgrav/grav |
|
Tue, 07 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Grav CMS via SVG Upload |
Mon, 06 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getgrav grav
|
|
| CPEs | cpe:2.3:a:getgrav:grav:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Getgrav grav
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Grav CMS SVG Upload | XML External Entity Vulnerability in Grav CMS via SVG Upload |
| First Time appeared |
Getgrav
Getgrav grav Cms |
|
| Vendors & Products |
Getgrav
Getgrav grav Cms |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | XML External Entity Vulnerability in Grav CMS SVG Upload |
Mon, 30 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-611 | |
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-30T19:20:28.827Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-29924
Updated: 2026-03-30T19:18:47.139Z
Status : Analyzed
Published: 2026-03-30T19:16:24.470
Modified: 2026-04-06T15:58:27.763
Link: CVE-2026-29924
No data.
OpenCVE Enrichment
Updated: 2026-04-07T08:08:41Z