ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36955”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36955
Published
2026-01-26
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site.